Secunia Logo
 
CVE Reference: CVE-2005-2871
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2871

Description:
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22207

UBUNTU
  http://www.ubuntu.com/usn/usn-181-1

ST
  1014877

SREASON
  http://securityreason.com/securityalert/83

SAID
  Secunia Advisory: SA16764
  Secunia Advisory: SA16766
  Secunia Advisory: SA16767
  Secunia Advisory: SA17042
  Secunia Advisory: SA17090
  Secunia Advisory: SA17284
  Secunia Advisory: SA17263

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-791.html
  http://www.redhat.com/support/errata/RHSA-2005-769.html
  http://www.redhat.com/support/errata/RHSA-2005-768.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1287
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:584

OSVDB
  19255

MISC
  http://www.securiteam.com/securitynews/5RP0B0UGVW.html
  http://www.security-protocols.com/advisory/sp-x17-advisory.txt
  http://www.security-protocols.com/firefox-death.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:174

HP

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200509-11.xml

FULLDISC
  http://archives.neohapsis.com/archives/fulldisclosure/2005-09/0316.html
  http://marc.theaimsgroup.com/?l=full-disclosure&m=112624614008387&w=2

FEDORA
  http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html

DEBIAN
  http://www.debian.org/security/2005/dsa-866
  http://www.debian.org/security/2005/dsa-868
  http://www.debian.org/security/2005/dsa-837

CONFIRM
  http://www.mozilla.org/security/announce/mfsa2005-57.html

CIAC
  http://www.ciac.org/ciac/bulletins/p-303.shtml

CERT-VN
  573857

BID
  14784


Return to the previous page.