CVE Database
/

CVE-2004-1316

Back to search

CVE-2004-1316

Published: Dec 31, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.

VendorProductVersions

n/a

n/a

affected
n/a

References

19823
third-party-advisory
x_refsource_SECUNIA
HPSBTU01114
vendor-advisory
x_refsource_HP
12131
vdb-entry
x_refsource_BID
mozilla-nntp-bo(18711)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:100052
vdb-entry
signature
x_refsource_OVAL
SUSE-SA:2006:022
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:9808
vdb-entry
signature
x_refsource_OVAL
RHSA-2005:038
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now