Secunia Advisory SA10292Mozilla "irc:" URI Handler Denial of Service
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A problem has been reported in Mozilla, which can be exploited by malicious people to cause a DoS (Denial of Service). The problem is caused due to an error in the Chatzilla component. When an overly long string (about 40K) is supplied as a network name (e.g. via the "irc:" URI handler), a recursive function in "js3250.dll" will consume all allocated stack space and eventually cause an access violation, which crashes Mozilla. This issue has been confirmed Chatzilla versions 0.9.35 and 0.9.48 in Mozilla 1.4 and 1.5 for Windows. Other versions are likely also affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
141 views | ![]() |
| Ubuntu update for thunderbird | |
114 views | ![]() |
| Debian update for php5 | |