CVE-2008-0017
Last modified
CVE-2008-0017 is a vulnerability of currently unknown severity. The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.. EPSS estimates a 7.68% chance of exploitation in the next 30 days.
Description
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.18 |
| Mozilla | Firefox | >= 3.0, < 3.0.4 |
| Mozilla | Seamonkey | >= 1.0, < 1.1.13 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 8.10 |
| Debian | Debian Linux | 4.0 |
| Debian | Debian Linux | 5.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
- http://secunia.com/advisories/32713Third Party Advisory
- http://secunia.com/advisories/32714Third Party Advisory
- http://secunia.com/advisories/32721Third Party Advisory
- http://secunia.com/advisories/32778Third Party Advisory
- http://secunia.com/advisories/32845Third Party Advisory
- http://secunia.com/advisories/32853Third Party Advisory
- http://secunia.com/advisories/33433Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://ubuntu.com/usn/usn-667-1Third Party Advisory
- http://www.debian.org/security/2008/dsa-1669Third Party Advisory
- http://www.debian.org/security/2008/dsa-1671Third Party Advisory
- http://www.debian.org/security/2009/dsa-1697Third Party Advisory
- http://www.iss.net/threats/311.htmlBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0977.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0978.htmlThird Party Advisory
- http://www.securityfocus.com/bid/32281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021185Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3146Third Party Advisory
- http://www.vupen.com/english/advisories/2009/0977Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=443299Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
- http://secunia.com/advisories/32713Third Party Advisory
- http://secunia.com/advisories/32714Third Party Advisory
- http://secunia.com/advisories/32721Third Party Advisory
- http://secunia.com/advisories/32778Third Party Advisory
- http://secunia.com/advisories/32845Third Party Advisory
- http://secunia.com/advisories/32853Third Party Advisory
- http://secunia.com/advisories/33433Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://ubuntu.com/usn/usn-667-1Third Party Advisory
- http://www.debian.org/security/2008/dsa-1669Third Party Advisory
- http://www.debian.org/security/2008/dsa-1671Third Party Advisory
- http://www.debian.org/security/2009/dsa-1697Third Party Advisory
- http://www.iss.net/threats/311.htmlBroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0977.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0978.htmlThird Party Advisory
- http://www.securityfocus.com/bid/32281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021185Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3146Third Party Advisory
- http://www.vupen.com/english/advisories/2009/0977Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=443299Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0017?
How severe is CVE-2008-0017?
How do I fix CVE-2008-0017?
Are you affected by CVE-2008-0017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
