CVE-2008-5016

MEDIUM

Description

The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.

References

http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html

http://secunia.com/advisories/32684

http://secunia.com/advisories/32694

http://secunia.com/advisories/32695

http://secunia.com/advisories/32713

http://secunia.com/advisories/32721

http://secunia.com/advisories/32778

http://secunia.com/advisories/32798

http://secunia.com/advisories/34501

http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1

http://ubuntu.com/usn/usn-667-1

http://www.mandriva.com/security/advisories?name=MDVSA-2008:230

http://www.mandriva.com/security/advisories?name=MDVSA-2008:235

http://www.mozilla.org/security/announce/2008/mfsa2008-52.html

http://www.redhat.com/support/errata/RHSA-2008-0976.html

http://www.redhat.com/support/errata/RHSA-2008-0977.html

http://www.redhat.com/support/errata/RHSA-2008-0978.html

http://www.securityfocus.com/bid/32281

http://www.securitytracker.com/id?1021183

http://www.us-cert.gov/cas/techalerts/TA08-319A.html

http://www.vupen.com/english/advisories/2008/3146

http://www.vupen.com/english/advisories/2009/0977

https://bugzilla.mozilla.org/buglist.cgi?bug_id=439206,453406,458637,444864,452157,449111,444260,457375,433429,443528,430394

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11356

https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html

https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html

Details

Source: MITRE

Published: 2008-11-13

Updated: 2017-09-29

Type: CWE-399

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 3.0.3 (inclusive)

cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* versions up to 1.1.12 (inclusive)

cpe:2.3:a:mozilla:thunderbird:2.0.0.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.12:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:2.0.0.14:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* versions up to 2.0.0.17 (inclusive)

Tenable Plugins

View all (47 total)

IDNameProductFamilySeverity
67766Oracle Linux 5 : firefox (ELSA-2008-0978)NessusOracle Linux Local Security Checks
critical
67765Oracle Linux 3 / 4 : seamonkey (ELSA-2008-0977)NessusOracle Linux Local Security Checks
critical
67764Oracle Linux 4 : thunderbird (ELSA-2008-0976)NessusOracle Linux Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
60498Scientific Linux Security Update : thunderbird on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
60495Scientific Linux Security Update : seamonkey on SL3.x, SL4.x i386/x86_64NessusScientific Linux Local Security Checks
critical
60494Scientific Linux Security Update : firefox on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
43715CentOS 4 / 5 : firefox (CESA-2008:0978)NessusCentOS Local Security Checks
critical
43714CentOS 4 / 5 : thunderbird (CESA-2008:0976)NessusCentOS Local Security Checks
critical
41511SuSE 10 Security Update : gecko-sdk and mozilla-xulrunner (ZYPP Patch Number 5813)NessusSuSE Local Security Checks
critical
41465SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 5826)NessusSuSE Local Security Checks
critical
40131openSUSE Security Update : seamonkey (seamonkey-326)NessusSuSE Local Security Checks
critical
40072openSUSE Security Update : mozilla-xulrunner181 (mozilla-xulrunner181-329)NessusSuSE Local Security Checks
critical
39894openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-333)NessusSuSE Local Security Checks
critical
39884openSUSE Security Update : MozillaFirefox (MozillaFirefox-334)NessusSuSE Local Security Checks
critical
37735Fedora 10 : thunderbird-2.0.0.18-1.fc10 (2008-9901)NessusFedora Local Security Checks
critical
37649Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : mozilla-thunderbird, thunderbird vulnerabilities (USN-668-1)NessusUbuntu Local Security Checks
critical
37572Mandriva Linux Security Advisory : firefox (MDVSA-2008:230)NessusMandriva Local Security Checks
critical
37099Mandriva Linux Security Advisory : mozilla-thunderbird (MDVSA-2008:235)NessusMandriva Local Security Checks
critical
36711Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : firefox, firefox-3.0, xulrunner-1.9 vulnerabilities (USN-667-1)NessusUbuntu Local Security Checks
critical
36485CentOS 3 / 4 : seamonkey (CESA-2008:0977)NessusCentOS Local Security Checks
critical
34967SuSE 10 Security Update : gecko-sdk and mozilla-xulrunner (ZYPP Patch Number 5811)NessusSuSE Local Security Checks
critical
34961openSUSE 10 Security Update : seamonkey (seamonkey-5815)NessusSuSE Local Security Checks
critical
34960openSUSE 10 Security Update : mozilla-xulrunner181 (mozilla-xulrunner181-5820)NessusSuSE Local Security Checks
critical
34958openSUSE 10 Security Update : MozillaThunderbird (MozillaThunderbird-5825)NessusSuSE Local Security Checks
critical
34957openSUSE 10 Security Update : MozillaFirefox (MozillaFirefox-5812)NessusSuSE Local Security Checks
critical
34941SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 5786)NessusSuSE Local Security Checks
critical
34842RHEL 4 / 5 : thunderbird (RHSA-2008:0976)NessusRed Hat Local Security Checks
critical
34837Fedora 9 : thunderbird-2.0.0.18-1.fc9 (2008-9859)NessusFedora Local Security Checks
critical
34836Fedora 8 : thunderbird-2.0.0.18-1.fc8 (2008-9807)NessusFedora Local Security Checks
critical
4762Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
medium
34819Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesNessusWindows
high
34778Fedora 9 : Miro-1.2.7-2.fc9 / cairo-dock-1.6.3.1-1.fc9.1 / chmsee-1.0.1-6.fc9 / devhelp-0.19.1-6.fc9 / etc (2008-9669)NessusFedora Local Security Checks
critical
34777Fedora 8 : Miro-1.2.7-2.fc8 / blam-1.8.3-19.fc8 / cairo-dock-1.6.3.1-1.fc8.1 / chmsee-1.0.0-5.31.fc8 / etc (2008-9667)NessusFedora Local Security Checks
critical
34771FreeBSD : mozilla -- multiple vulnerabilities (f29fea8f-b19f-11dd-a55e-00163e000016)NessusFreeBSD Local Security Checks
critical
4753SeaMonkey < 1.1.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
4752Mozilla Firefox 3.x < 3.0.4 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
4751Mozilla Firefox < 2.0.0.18 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
34768SeaMonkey < 1.1.13 Multiple VulnerabilitiesNessusWindows
high
34767Firefox 3.0.x < 3.0.4 Multiple VulnerabilitiesNessusWindows
high
34766Firefox < 2.0.0.18 Multiple VulnerabilitiesNessusWindows
high
34764RHEL 4 / 5 : firefox (RHSA-2008:0978)NessusRed Hat Local Security Checks
critical
34763RHEL 2.1 / 3 / 4 : seamonkey (RHSA-2008:0977)NessusRed Hat Local Security Checks
critical
801316Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
800876SeaMonkey < 1.1.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800751Firefox 3.x < 3.0.4 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800741Firefox < 2.0.0.18 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high