Free Republic
Browse · Search
News/Activism
Topics · Post Article

Uber-Geeks please see the "technical" version of this alert at:

http://www.us-cert.gov/cas/techalerts/TA04-261A.html

1 posted on 09/17/2004 4:02:09 PM PDT by Stoat
[ Post Reply | Private Reply | View Replies ]


To: Stoat
Quite a few actually

Several vulnerabilities have been reported in the Mozilla web browser and derived products. More detailed information is available in the individual vulnerability notes:

VU#414240 - Mozilla Mail vulnerable to buffer overflow via writeGroup() function in nsVCardObj.cpp

Mozilla Mail contains a stack overflow vulnerability in the display routines for VCards. By sending an email message with a crafted VCard, a remote attacker may be able to execute arbitrary code on the victim's machine with the privileges of the current user. This can be exploited in the preview mode as well.

VU#847200 - Mozilla contains integer overflows in bitmap image decoder

A vulnerability in the way Mozilla and its derived programs handle certain bitmap images could allow a remote attacker to execute arbitrary code on a vulnerable system.

VU#808216 - Mozilla contains heap overflow in UTF8 conversion of hostname portion of URLs

A vulnerability in the way Mozilla and its derived programs handle certain malformed URLs could allow a remote attacker to execute arbitrary code on a vulnerable system.

VU#125776 - Multiple buffer overflows in Mozilla POP3 protocol handler

There are multiple buffer overflow vulnerabilities in the Mozilla POP3 protocol handler that could allow a malicious POP3 server to execute arbitrary code on the affected system.

VU#327560 - Mozilla "send page" feature contains a buffer overflow vulnerability

There is a buffer overflow vulnerability in the Mozilla "send page" feature that could allow a remote attacker to execute arbitrary code.

VU#651928 - Mozilla allows arbitrary code execution via link dragging

A vulnerability affecting Mozilla web browsers may allow violation of cross-domain scripting policies and possibly execute code originating from a remote source.

2 posted on 09/17/2004 4:03:52 PM PDT by Centurion2000 (Truth, Justice and the Texan Way)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat
And the beast shall be made legion. Its numbers shall be increased a thousand thousand fold. The din of a million keyboards like unto a great storm shall cover the earth, and the followers of Mammon shall tremble.

from The Book of Mozilla, 3:31

(Red Letter Edition)

3 posted on 09/17/2004 4:04:01 PM PDT by steveo (Member: Fathers Against Rude Television)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

And I thought it was regarded as a more secure alternative to Explorer.


4 posted on 09/17/2004 4:04:42 PM PDT by Buford T. Justice
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

Thanks for the post. Updated.


7 posted on 09/17/2004 4:16:00 PM PDT by Arkinsaw
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

Ah, now we know what the geeks in Redmond write in their spare time, now that their stock options are tanking.


9 posted on 09/17/2004 4:21:38 PM PDT by FreedomFarmer (Less carrot, more STICK!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

My FireFox and Thunderbird are up to date! I'm saved!!!


11 posted on 09/17/2004 4:36:01 PM PDT by Solamente
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

BTTT


12 posted on 09/17/2004 4:38:01 PM PDT by Fiddlstix (This Tagline for sale. (Presented by TagLines R US))
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

I am using Firebird 0.7. Which do I download. Mozilla, Firefox, or Thunderbird? I don't use the mail utility.


14 posted on 09/17/2004 4:38:52 PM PDT by fritzz (Power tends to corrupt, and absolute power corrupts absolutely - Lord Acton)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

But, but, but ... I thought this was impossible! They said that only Microsoft products have vulnerabilities and that I would become 50 pounds lighter, a foot taller, and my winkie would lengthen by 2 inches if I stopped using them!


17 posted on 09/17/2004 4:43:39 PM PDT by asgardshill (By direct order, I LOVE ALAN KEYES!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

Thanks for posting this.


23 posted on 09/17/2004 5:03:03 PM PDT by DB (©)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

bookmark


25 posted on 09/17/2004 5:09:22 PM PDT by WestCoastGal (Jr" I dunno what happened, it just felt like the hand of God came over and hit me real hard")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

Updated, and thankee kindly for the headsup!


36 posted on 09/17/2004 9:38:17 PM PDT by Titan Magroyne (Uniform of the day: Freepajamas)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: RhoTheta

Ping.


39 posted on 09/18/2004 7:30:34 AM PDT by Egon (I will quit this post only when properly relieved.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

thanks for the tip.


40 posted on 09/20/2004 12:39:00 AM PDT by AmericanVictory (Should we be more like them, or they like us?)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Stoat

bump for later


46 posted on 09/20/2004 1:55:53 PM PDT by eyespysomething (I'm typing up lottery tickets. I mean, as long as the content is true the rest doesn't matter.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson