Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-4070
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4070

Description:
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/45426

UBUNTU
  http://www.ubuntu.com/usn/usn-647-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422
  http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123

SAID
  Secunia Advisory: SA32010
  Secunia Advisory: SA32082
  Secunia Advisory: SA32044
  Secunia Advisory: SA32092
  Secunia Advisory: SA32025
  Secunia Advisory: SA33433
  Secunia Advisory: SA33434
  Secunia Advisory: SA34501

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0908.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:206

DEBIAN
  http://www.debian.org/security/2009/dsa-1697
  http://www.debian.org/security/2009/dsa-1696

CONFIRM
  http://www.mozilla.org/security/announce/2008/mfsa2008-46.html

BID
  31411


Return to the previous page.