CVE Vulnerabilities

CVE-2005-2871

Published: Sep 09, 2005 | Modified: May 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all soft hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 1.0 (including) 1.0 (including)
Firefox Mozilla 1.0.1 (including) 1.0.1 (including)
Firefox Mozilla 1.0.2 (including) 1.0.2 (including)
Firefox Mozilla 1.0.3 (including) 1.0.3 (including)
Firefox Mozilla 1.0.4 (including) 1.0.4 (including)
Firefox Mozilla 1.0.5 (including) 1.0.5 (including)
Firefox Mozilla 1.0.6 (including) 1.0.6 (including)
Firefox Mozilla 1.5-beta1 (including) 1.5-beta1 (including)
Red Hat Enterprise Linux 2.1 RedHat mozilla *
Red Hat Enterprise Linux 3 RedHat mozilla *
Red Hat Enterprise Linux 4 RedHat firefox-0:1.0.6-1.4.2 *
Red Hat Enterprise Linux 4 RedHat mozilla *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.0.7-1.4.1 *
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu edgy *
Firefox Ubuntu feisty *
Firefox-granparadiso Ubuntu devel *
Lightning-sunbird Ubuntu devel *
Midbrowser Ubuntu devel *
Mozilla Ubuntu dapper *
Mozilla Ubuntu edgy *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *

References