Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla  Firefox, Thunderbird, SeaMonkey, NSS multiple security vulnerabilities

  Mozilla Foundation Security Advisory 2009-46

  Mozilla Foundation Security Advisory 2009-45

  Mozilla Foundation Security Advisory 2009-44

  Mozilla Foundation Security Advisory 2009-43

From:MOZILLA
Date:07.08.2009
Subject:Mozilla Foundation Security Advisory 2009-38

Mozilla Foundation Security Advisory 2009-38

Title: Data corruption with SOCKS5 reply containing DNS name longer than 15 characters
Impact: Low
Announced: July 21, 2009
Reporter: Andrej Andolsek
Products: Firefox

Fixed in: Firefox 3.5.2
 Firefox 3.0.12
Description

Andrej Andolsek reported that when Firefox receives a reply from a SOCKS5 proxy which contains a DNS name longer than 15 characters, the subsequent data stream in the response can become corrupted. There was no evidence of memory corruption, however, and the severity of the issue was determined to be low.
References

   * https://bugzilla.mozilla.org/show_bug.cgi?id=459524
   * CVE-2009-2470

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server