Mozilla Foundation Security Advisory 2006-49
Heap buffer overwrite on malformed VCard
- Announced
- July 25, 2006
- Reporter
- Daniel Veditz (Mozilla)
- Impact
- Critical
- Products
- SeaMonkey, Thunderbird
- Fixed in
-
- SeaMonkey 1.0.3
- Thunderbird 1.5.0.5
Description
A VCard attachment with a malformed base64 field (such as a photo) can trigger a heap buffer overwrite. These have proven exploitable in the past, though in this case the overwrite is accompanied by an integer underflow that would attempt to copy more data than the typical machine has, leading to a crash.
Workaround
Turn off the in-line display of attachments and do not click on or open VCard attachments until you upgrade to a fixed version.
References
https://bugzilla.mozilla.org/show_bug.cgi?id=339740
CVE-2006-3804