CVE-2008-0016

Published: 24 September 2008

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream
Released (2.0.0.17)
firefox-3.0
Launchpad, Ubuntu, Debian
Upstream
Released (3.0.3)
iceape
Launchpad, Ubuntu, Debian
Upstream Needs triage

seamonkey
Launchpad, Ubuntu, Debian
Upstream
Released (1.1.12)
xulrunner
Launchpad, Ubuntu, Debian
Upstream
Released (1.8.1.18)
xulrunner-1.9
Launchpad, Ubuntu, Debian
Upstream
Released (1.9.0.3)