5
CVSSv2

CVE-2005-0989

Published: 02/05/2005 Updated: 03/05/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote malicious users to read portions of heap memory in a Javascript string via the lambda replace method.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.0.1

mozilla firefox 1.0.2

mozilla mozilla 1.7.6

netscape navigator 7.2

Vendor Advisories

Synopsis firefox security update Type/Severity Security Advisory: Important Topic Updated firefox packages that fix various security bugs are now availableThis update has been rated as having Important security impact by the RedHat Security Response Team Description Mozilla Firefox is an ...
Synopsis Mozilla security update Type/Severity Security Advisory: Important Topic Updated Mozilla packages that fix various security bugs are now availableThis update has been rated as having Important security impact by the RedHat Security Response Team Description Mozilla is an open sou ...
Synopsis Mozilla security update Type/Severity Security Advisory: Important Topic Updated mozilla packages that fix various security bugs are now availableThis update has been rated as having Important security impact by the RedHat Security Response Team Description Mozilla is an open sou ...
Synopsis thunderbird security update Type/Severity Security Advisory: Important Topic Updated thunderbird package that fixes various bugs is now available forRed Hat Enterprise Linux 4This update has been rated as having important security impact by the RedHat Security Response Team Description ...
Several problems have been discovered in Mozilla Thunderbird, the standalone mail client of the Mozilla suite The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2005-0989 Remote attackers could read portions of heap memory into a Javascript string via the lambda replace method CAN-2005-1159 The Ja ...
USN-149-1 fixed some vulnerabilities in the Ubuntu 504 (Hoary Hedgehog) version of Firefox The version shipped with Ubuntu 410 (Warty Warthog) is also vulnerable to these flaws, so it needs to be upgraded as well Please see ...
Vladimir V Perepelitsa discovered a bug in Thunderbird’s handling of anonymous functions during regular expression string replacement A malicious HTML email could exploit this to capture a random block of client memory (CAN-2005-0989) ...

Exploits

source: wwwsecurityfocuscom/bid/12988/info Mozilla Suite/Firefox are reported prone to a memory-disclosure vulnerability This issue can allow a remote attacker to access arbitrary heap memory Due to an error in the way 'replace()' handles lambda expressions, a remote attacker can access arbitrary heap memory from a vulnerable client ...