Mozilla Firefox Lets Remote Users Set Cookie Values to Deny Service
|
|
SecurityTracker Alert ID: 1018163
|
|
SecurityTracker URL: http://securitytracker.com/id?1018163
|
|
CVE Reference: CVE-2007-1362
(Links to External Site)
|
Date: May 31 2007
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Mozilla Foundation Security Advisory
|
Version(s): 1.5 prior to 1.5.0.12, 2.0 prior to 2.0.0.4
|
Description: A vulnerability was reported in Mozilla Firefox. A remote user can cause denial of service conditions.
A remote user can create HTML that, when loaded by the target user, will set an exceptionally long cookie value, causing the target
user's browser to consume excessive memory and disk resources. A specially crafted cookie path and name value may allow a remote
user to set a secure cookie from a non-secure site.
Nicolas Derouet reported this vulnerability.
|
Impact: A remote user can cause denial of service conditions.
|
Solution: The vendor has issued a fixed version (1.5.0.12, 2.0.0.4).
The Mozilla advisory is available at:
http://www.mozilla.org/security/announce/2007/mfsa2007-14.html
|
Vendor URL: www.mozilla.org/security/announce/2007/mfsa2007-14.html (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 30 May 2007 23:12:51 -0400
Subject: Mozilla Firefox
|
http://www.mozilla.org/security/announce/2007/mfsa2007-14.html
CVE-2007-1362
|
|