CVE-2009-5017
published 2010-11-12CVE-2009-5017: Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.87%
77.2th percentile
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.6 | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p83q-cg3p-77f9: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2009-5017 [MEDIUM] CWE-79 GHSA-p83q-cg3p-77f9: Mozilla Firefox before 3
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
Red Hat
Firefox: overlong UTF-8 seqence detection problem
vendor_redhat·2009-08-21·CVSS 4.3
CVE-2009-5017 [MEDIUM] Firefox: overlong UTF-8 seqence detection problem
Firefox: overlong UTF-8 seqence detection problem
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem
bugzilla·2010-11-23·CVSS 4.3
CVE-2009-5017 [MEDIUM] CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem
CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-5017 to
the following vulnerability:
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8
encoding, which makes it easier for remote attackers to bypass cross-site
scripting (XSS) protection mechanisms via a crafted string, a different
vulnerability than CVE-2010-1210.
References:
[1] http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html
[2] http://hg.mozilla.org/releases/mozilla-1.9.2/rev/e42c563313a0
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=511859
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=522634
Reference public PoC:
[5] https://bugzilla.mozilla.org/show_bug.cgi?id=511859#c1
Upstream change
Bugzilla
CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem [fedora-12]
bugzilla·2010-11-23·CVSS 4.3
CVE-2009-5017 [MEDIUM] CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem [fedora-12]
CVE-2009-5017 Firefox: overlong UTF-8 seqence detection problem [fedora-12]
fedora-12 tracking bug for firefox: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora 12 changed to end-of-life (EOL) status on 2010-12-02. Fedora 12 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.
If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version.
Thank you for reporting this bug and we are sorry it could not be fixed.
http://hg.mozilla.org/releases/mozilla-1.9.2/rev/e42c563313a0http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=511859https://bugzilla.mozilla.org/show_bug.cgi?id=522634http://hg.mozilla.org/releases/mozilla-1.9.2/rev/e42c563313a0http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=511859https://bugzilla.mozilla.org/show_bug.cgi?id=522634
2010-11-12
Published