Bug 64571 (CVE-2004-1316)

Summary: VUL-0: CVE-2004-1316: buffer overflow in NNTP handling in Mozilla <= 1.7.3
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: Wolfgang Rosenauer <stark>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: CVE-2004-1316: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Marcus Meissner 2005-01-03 23:52:27 UTC
From: http://www.mozillazine.org/talkback.html?article=5844 
 
NNTP Security Flaw in Mozilla 1.7.3 and Below 
 
 
Friday December 31st, 2004 
 
 
Jonik writes: "A security vulnerability has been found that affects Mozilla 
1.7.3 and earlier versions. Apparently there is a flaw in the NNTP handling 
code which may cause heap overflow and allow remote attacker to execute 
arbitrary code." All the latest Mozilla versions are immune but there also 
appears to be some dispute as to whether this vulnerability was ever 
practically exploitable in the first place.
Comment 1 Marcus Meissner 2005-01-03 23:52:27 UTC
<!-- SBZ_reproduce  -->
n/a
Comment 2 Marcus Meissner 2005-01-03 23:54:09 UTC
https://bugzilla.mozilla.org/show_bug.cgi?id=264388 
 
no CAN assigned yet I think. 
Comment 3 Wolfgang Rosenauer 2005-01-04 16:24:13 UTC
working on it...
Comment 4 Wolfgang Rosenauer 2005-01-11 17:07:25 UTC
submitted for all mozillas and thunderbirds.
Comment 5 Ludwig Nussel 2005-01-14 20:11:49 UTC
CAN-2004-1316 
Comment 6 Thomas Biege 2009-10-13 20:09:58 UTC
CVE-2004-1316: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)