blog.mozilla.comConfirmation
http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479 CVE-2009-2479
Mozilla Firefox 3.5 - Unicode Remote Buffer Overflow (PoC)
Record summary
CVE-2009-2479 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.
Description
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox 3.5 - Unicode Remote Buffer Overflow (PoC)ExploitDB exploitby Andrew HaynesNot analyzed1 file
References
1255931vdb entry
http://osvdb.org/55931 websecurity.com.ua
http://websecurity.com.ua/3338 9158exploit
http://www.exploit-db.com/exploits/9158 20090719 DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chromemailing list
http://www.securityfocus.com/archive/1/505092/100/0/threaded 35707vdb entry
http://www.securityfocus.com/bid/35707 1022580vdb entry
http://www.securitytracker.com/id?1022580 bugzilla.mozilla.orgConfirmation
https://bugzilla.mozilla.org/show_bug.cgi?id=504342 bugzilla.mozilla.org
https://bugzilla.mozilla.org/show_bug.cgi?id=504343 firefox-unicode-data-dos(51729)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51729 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-2479 FEDORA-2009-7898Vendor advisory
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html