Vulnerability Description
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.19 |
| Mozilla | Seamonkey | >= 1.0, < 1.1.14 |
| Canonical | Ubuntu Linux | 8.04 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33188Third Party Advisory
- http://secunia.com/advisories/33189Third Party Advisory
- http://secunia.com/advisories/33203Third Party Advisory
- http://secunia.com/advisories/33216Third Party Advisory
- http://secunia.com/advisories/33421Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:245Third Party Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-60.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-1036.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-1037.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-0002.htmlThird Party Advisory
- http://www.securityfocus.com/bid/32882Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1021417Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2009/0977Third Party Advisory
FAQ
What is CVE-2008-5502?
CVE-2008-5502 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that tr...
How severe is CVE-2008-5502?
CVE-2008-5502 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5502?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Canonical Ubuntu Linux.