Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://isec.pl/vulnerabilities/isec-0020-mozilla.txt http://marc.theaimsgroup.com/?l=bugtraq&m=110436284718949 http://www.vuxml.org/freebsd/3fbf9db2-658b-11d9-abad-000a95bc6fae.html
Insight
The following packages are affected:
de-netscape7
fr-netscape7
ja-netscape7
netscape7
pt_BR-netscape7
mozilla-gtk1
linux-mozilla
linux-mozilla-devel
mozilla
de-linux-netscape
fr-linux-netscape
ja-linux-netscape
linux-netscape
mozilla+ipv6
mozilla-embedded
mozilla-gtk2
mozilla-gtk
CVE-2004-1316
Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.
Severity
Classification
-
CVE CVE-2004-1316 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities