Mozilla多个内存破坏漏洞

漏洞信息详情

Mozilla多个内存破坏漏洞

漏洞简介

Mozilla存在漏洞。远程攻击者可以借助网页导致服务拒绝(空解引用或无限循环引起的应用程序崩溃)。这种网页后跟包含(1) TEXTAREA,(2) INPUT, (3) FRAMESET或者(4)IMG tag的空字符和一些跟踪字符。

漏洞公告

These issues have been reportedly addressed in Mozilla snapshots. This has not been confirmed by Symantec.
SGI has released an advisory 20050304-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.
RedHat has released advisory RHSA-2005:323 to address this issue. Please see the referenced advisory to obtain fix information.
RedHat Fedora Legacy has released advisory FLSA:152883 addressing this and other issues for RedHat Linux 7.3, 9 and for Fedora Core 1 and Core 2. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Mozilla Browser 1.2.1

Mozilla Browser 1.4.1

Mozilla Browser 1.6

  • Red Hat Fedora epiphany-1.2.10-0.2.3.legacy.i386.rpmRed Hat Fedora i386

参考网址

来源: BID
名称: 11439
链接:http://www.securityfocus.com/bid/11439

来源: REDHAT
名称: RHSA-2005:323
链接:http://www.redhat.com/support/errata/RHSA-2005-323.html

来源: XF
名称: mozilla-html-tags-dos(17805)
链接:http://xforce.iss.net/xforce/xfdb/17805

来源: SECTRACK
名称: 1011810
链接:http://securitytracker.com/id?1011810

来源: OVAL
名称: oval:org.mitre.oval:def:10227
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10227

来源: BUGTRAQ
名称: 20041018 Web browsers – a mini-farce
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109811406620511&w=2

来源: FULLDISC
名称: 20041018 Web browsers – a mini-farce
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.html

来源: lcamtuf.coredump.cx
链接:http://lcamtuf.coredump.cx/mangleme/gallery/

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享