Nine vulnerabilities were identified in Mozilla Suite and Mozilla Firefox, which may be exploited by remote attackers to execute arbitrary commands or conduct spoofing and cross site scripting attacks.
The first flaw is due to a buffer overflow error when handling malformed URLs containing "soft hyphen" characters, which could be exploited by remote attackers to take complete control of an affected system via specially crafted Web pages. For additional information, see : FrSIRT/ADV-2005-1690
The second vulnerability is due to a heap overflow error when processing specially crafted XBM images, which could be exploited by malicious websites to compromise a vulnerable system [...]
References
http://www.frsirt.com/english/advisories/2005/1824
http://www.mozilla.org/security/announce/mfsa2005-59.html
http://www.mozilla.org/security/announce/mfsa2005-58.html
http://www.mozilla.org/security/announce/mfsa2005-57.html
Credits
Vulnerabilities reported by jackerror, Mats Palmgren, moz_bug_r_a4, Georgi Guninski, heatsync and shutdown.
ChangeLog
2005-09-22 : Initial release
2005-10-01 : Updated Affected Products and Solution
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.