Vulnerabilità: CVE-2005-4134

Mozilla Firefox 1.5, Netscape 8.0.4 e 7.2, e K-Meleon prima 0.9.12 consente agli aggressori remoti di causare un denial of service (consumo di CPU e l’avvio dell’applicazione ritardata) tramite un sito web con un grande titolo, che viene registrato nella storia .dat ma non elaborati in modo efficiente durante l’avvio. NOTA: nonostante i rapporti iniziali, il venditore di Mozilla non crede che la questione possa essere utilizzato per attivare un crash o overflow del buffer in Firefox. Inoltre, è stato riportato in modo indipendente che Netscape 8.1 non ha questo problema.


http://www.securityfocus.com/bid/15773
http://www.securityfocus.com/bid/16476
http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm
http://www.mozilla.org/security/announce/mfsa2006-03.html
http://www.debian.org/security/2006/dsa-1044
http://www.debian.org/security/2006/dsa-1046
http://www.debian.org/security/2006/dsa-1051
http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html
http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html
http://www.securityfocus.com/archive/1/425978/100/0/threaded
http://www.securityfocus.com/archive/1/425975/100/0/threaded
http://marc.info/?l=full-disclosure&m=113405896025702&w=2
http://marc.info/?l=full-disclosure&m=113404911919629&w=2
http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml
http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.mandriva.com/security/advisories?name=MDKSA-2006:036
http://www.mandriva.com/security/advisories?name=MDKSA-2006:037
http://www.mozilla.org/security/history-title.html
http://www.networksecurity.fi/advisories/netscape-history.html
http://www.osvdb.org/21533
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11382
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1619
http://www.redhat.com/support/errata/RHSA-2006-0199.html
http://www.redhat.com/support/errata/RHSA-2006-0200.html
http://securitytracker.com/id?1015328
http://secunia.com/advisories/17934
http://secunia.com/advisories/17944
http://secunia.com/advisories/17946
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://secunia.com/advisories/18705
http://secunia.com/advisories/18706
http://secunia.com/advisories/18708
http://secunia.com/advisories/18709
http://secunia.com/advisories/19230
http://secunia.com/advisories/19746
http://secunia.com/advisories/19759
http://secunia.com/advisories/19852
http://secunia.com/advisories/19862
http://secunia.com/advisories/19863
http://secunia.com/advisories/19902
http://secunia.com/advisories/19941
http://secunia.com/advisories/21033
http://secunia.com/advisories/21622
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1
https://usn.ubuntu.com/271-1/
https://usn.ubuntu.com/275-1/
http://www.vupen.com/english/advisories/2005/2805
http://www.vupen.com/english/advisories/2006/0413
http://www.vupen.com/english/advisories/2006/3391
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134


E' possibile lasciare un commento come utenti registrati al sito, accedendo tramite social, account wordpress oppure come utenti anonimi. Nel caso in cui si desideri lasciare un commento come utenti anonimi si verrà avvisati via email di un'eventuale risposta solo se si inserisce l'indirizzo email (facoltativo). L'inserimento di qualsiasi dato nei campi dei commenti è totalmente facoltativo. Chiunque decida di inserire un qualsiasi dato accetta il trattamento di questi ultimi per i fini inerenti al servizio ovvero la risposta al commento e le comunicazioni strettamente necessarie.


Rispondi