Mozilla Browser/Thunderbird SendUIDL POP3 Message Handling Remote Heap Overflow Vulnerability

Mozilla and Mozilla Thunderbird are reported prone to a remote heap overflow vulnerability. The issue is reported to exist due to a lack of sufficient boundary checks performed on POP3 data handled by SendUidl().

An attacker controlled POP3 mail server may exploit this condition by sending a specifically crafted email message to the affected mail client. This will result in the corruption of heap-based memory.


 

Privacy Statement
Copyright 2010, SecurityFocus