Executive Summary

Summary
Title Sun Alert 103121 Multiple Memory Corruption Vulnerabilities in Layout Engine for Mozilla 1.7
Informations
Name SUN-103121 First vendor Publication 2007-10-22
Vendor Sun Last vendor Modification 2007-10-22
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Mozilla v1.7

The Layout Engine in the Mozilla 1.7 application (see mozilla(1)) contains multiple memory corruption vulnerabilities which may allow a remote user who is able to create a web page which is visited by a local user using the Mozilla browser, or who sends a specially crafted email that is read by a local user using Mozilla, to either cause the Mozilla application to crash or execute arbitrary code with the privileges of the user running Mozilla. The ability of a remote user to cause the Mozilla application to crash is a type of Denial of Service (DoS).

The following Mozilla advisory describes four separate memory corruption issues:

http://www.mozilla.org/security/announce/2006/mfsa2006-65.html

This Sun Alert corresponds to two of the issues described in the Mozilla advisory above:

https://bugzilla.mozilla.org/show_bug.cgi?id=307809

https://bugzilla.mozilla.org/show_bug.cgi?id=351328

Also note that Mozilla 1.7 is not affected by the following two vulnerabilities mentioned in the advisory:

https://bugzilla.mozilla.org/show_bug.cgi?id=310267

https://bugzilla.mozilla.org/show_bug.cgi?id=350370

Additional references that describe these issues can be found in the following documents:

CVE-2006-5464 at http://www.security-database.com/detail.php?cve=CVE-2006-5464

CERT VU#495288 at http://www.security-database.com/detail.php?vu=VU495288

CERT Security Alert TA06-312A at http://www.us-cert.gov/cas/techalerts/TA06-312A.html

Avoidance: Workaround
State: Workaround
First released: 22-Oct-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_103121_multiple_memory

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:9304
 
Oval ID: oval:org.mitre.oval:def:9304
Title: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
Description: Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
Family: unix Class: vulnerability
Reference(s): CVE-2006-5464
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 10
Application 9
Application 8

OpenVAS Exploits

Date Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-06 (mozilla-thunderbird)
File : nvt/glsa_200612_06.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-07 (mozilla-firefox)
File : nvt/glsa_200612_07.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-08 (seamonkey)
File : nvt/glsa_200612_08.nasl
2008-01-17 Name : Debian Security Advisory DSA 1224-1 (mozilla)
File : nvt/deb_1224_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1225-1 (mozilla-firefox)
File : nvt/deb_1225_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1225-2 (mozilla-firefox)
File : nvt/deb_1225_2.nasl
2008-01-17 Name : Debian Security Advisory DSA 1227-1 (mozilla-thunderbird)
File : nvt/deb_1227_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
30301 Mozilla Multiple ProductLayout Engine Unspecified DoS

Nessus® Vulnerability Scanner

Date Description
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_MozillaFirefox-2258.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-382-1.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-381-1.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_seamonkey-2250.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaThunderbird-2252.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaFirefox-2251.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2006-205.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2006-206.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1199.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing one or more security updates.
File : fedora_2006-1191.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1194.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1192.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-06.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-08.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-07.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1227.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1225.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1224.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : The remote Windows host contains a mail client that is affected by multiple v...
File : mozilla_thunderbird_1508.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : A web browser on the remote host is prone to multiple flaws.
File : seamonkey_106.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : mozilla_firefox_1508.nasl - Type : ACT_GATHER_INFO