Secunia CSI 5.0
Products
Solutions
Customers
Partner
Resources
Company
Careers
Community

CVE Reference: CVE-2005-2871

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2871

Description:
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22207

UBUNTU
  http://www.ubuntu.com/usn/usn-181-1

ST
  1014877

SREASON
  http://securityreason.com/securityalert/83

SAID
  Secunia Advisory: SA16764
  Secunia Advisory: SA16766
  Secunia Advisory: SA16767
  Secunia Advisory: SA17042
  Secunia Advisory: SA17090
  Secunia Advisory: SA17284
  Secunia Advisory: SA17263

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-791.html
  http://www.redhat.com/support/errata/RHSA-2005-769.html
  http://www.redhat.com/support/errata/RHSA-2005-768.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:584
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1287
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9608

OSVDB
  19255

MISC
  http://www.securiteam.com/securitynews/5RP0B0UGVW.html
  http://www.security-protocols.com/advisory/sp-x17-advisory.txt
  http://www.security-protocols.com/firefox-death.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:174

HP

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200509-11.xml

FULLDISC
  http://archives.neohapsis.com/archives/fulldisclosure/2005-09/0316.html
  http://marc.theaimsgroup.com/?l=full-disclosure&m=112624614008387&w=2

FEDORA
  http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html

DEBIAN
  http://www.debian.org/security/2005/dsa-866
  http://www.debian.org/security/2005/dsa-837
  http://www.debian.org/security/2005/dsa-868

CONFIRM
  http://www.mozilla.org/security/announce/mfsa2005-57.html

CIAC
  http://www.ciac.org/ciac/bulletins/p-303.shtml

CERT-VN
  573857

BID
  14784


Return to the previous page.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability