CVE-2008-5500

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.
References
Link Resource
http://secunia.com/advisories/33184 Third Party Advisory
http://secunia.com/advisories/33188 Third Party Advisory
http://secunia.com/advisories/33189 Third Party Advisory
http://secunia.com/advisories/33203 Third Party Advisory
http://secunia.com/advisories/33204 Third Party Advisory
http://secunia.com/advisories/33205 Third Party Advisory
http://secunia.com/advisories/33216 Third Party Advisory
http://secunia.com/advisories/33231 Third Party Advisory
http://secunia.com/advisories/33232 Third Party Advisory
http://secunia.com/advisories/33408 Third Party Advisory
http://secunia.com/advisories/33415 Third Party Advisory
http://secunia.com/advisories/33421 Third Party Advisory
http://secunia.com/advisories/33433 Third Party Advisory
http://secunia.com/advisories/33434 Third Party Advisory
http://secunia.com/advisories/33523 Third Party Advisory
http://secunia.com/advisories/33547 Third Party Advisory
http://secunia.com/advisories/34501 Third Party Advisory
http://secunia.com/advisories/35080 Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-258748-1 Broken Link
http://www.debian.org/security/2009/dsa-1696 Third Party Advisory
http://www.debian.org/security/2009/dsa-1697 Third Party Advisory
http://www.debian.org/security/2009/dsa-1704 Third Party Advisory
http://www.debian.org/security/2009/dsa-1707 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:244 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:245 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:012 Third Party Advisory
http://www.mozilla.org/security/announce/2008/mfsa2008-60.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-1036.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-1037.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2009-0002.html Third Party Advisory
http://www.securityfocus.com/bid/32882 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1021417 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-690-2 Third Party Advisory
http://www.ubuntu.com/usn/usn-701-1 Third Party Advisory
http://www.ubuntu.com/usn/usn-701-2 Third Party Advisory
http://www.vupen.com/english/advisories/2009/0977 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=460803 Issue Tracking Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=464998 Issue Tracking Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/47406 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11053 Third Party Advisory
https://usn.ubuntu.com/690-1/ Third Party Advisory
https://usn.ubuntu.com/690-3/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-12-17 23:30

Updated : 2023-12-10 10:51


NVD link : CVE-2008-5500

Mitre link : CVE-2008-5500

CVE.ORG link : CVE-2008-5500


JSON object : View

Products Affected

mozilla

  • thunderbird
  • seamonkey
  • firefox

canonical

  • ubuntu_linux

debian

  • debian_linux
CWE
CWE-399

Resource Management Errors