CVE-2008-0017
published 2008-11-13CVE-2008-0017: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.68%
93.9th percentile
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
| mozilla | firefox | >= 3.0 < 3.0.4 | 3.0.4 |
| mozilla | seamonkey | >= 1.0 < 1.1.13 | 1.1.13 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.3
CVE-2008-4582 [MEDIUM] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
mo
Red Hat
Mozilla buffer overflow in http-index-format parser
vendor_redhat·2008-11-12·CVSS 9.3
CVE-2008-0017 [CRITICAL] Mozilla buffer overflow in http-index-format parser
Mozilla buffer overflow in http-index-format parser
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.
VMware
Updated ESX packages for libxml2, ucd-snmp, libtiff
vendor_vmware·2008-10-31·CVSS 6.5
CVE-2008-0960 [MEDIUM] Updated ESX packages for libxml2, ucd-snmp, libtiff
VMSA-2008-0017: Updated ESX packages for libxml2, ucd-snmp, libtiff
a. Updated ESX Service Console package libxml2 A denial of service flaw was found in the way libxml2 processes certain content. If an application that is linked against libxml2 processes malformed XML content, the XML content might cause the application to stop responding. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-3281 to this issue. Additionally the following was also fixed, but was missing in the security advisory. A heap-based buffer overflow flaw was found in the way libxml2 handled long XML entity names. If an application linked against libxml2 processed untrusted malformed XML content, it could cause the application to crash or, possibly, execute arbitrary code.
GHSA
GHSA-4386-5g32-qp3p: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3
ghsa_unreviewed·2022-05-01
CVE-2008-0017 [HIGH] CWE-119 GHSA-4386-5g32-qp3p: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1697http://www.iss.net/threats/311.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-54.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021185http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=443299https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1697http://www.iss.net/threats/311.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-54.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021185http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=443299https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
2008-11-13
Published