CVE-2002-1308: Buffer Overflow
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1308?
CVE-2002-1308 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2002-1308?
To fix CVE-2002-1308, update to the latest version of the affected Netscape or Mozilla browser.
What versions are affected by CVE-2002-1308?
CVE-2002-1308 affects multiple versions of Netscape Navigator and Mozilla, including versions up to 7.0 for Netscape and 1.1 for Mozilla.
What is the impact of CVE-2002-1308?
The impact of CVE-2002-1308 allows attackers to execute arbitrary code if a user interacts with a malicious .jar file.
Is there a workaround for CVE-2002-1308?
A possible workaround for CVE-2002-1308 is to avoid opening .jar files from untrusted sources until the vulnerability is patched.