CVE-2002-2338: Input Validation
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2338?
The severity of CVE-2002-2338 is classified as a denial of service vulnerability.
Which software versions are affected by CVE-2002-2338?
CVE-2002-2338 affects Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier versions.
How does CVE-2002-2338 allow a denial of service attack?
CVE-2002-2338 allows a denial of service by processing a mail message that contains a dot at a newline, interpreted as the end of the message.
What should be done to mitigate CVE-2002-2338?
To mitigate CVE-2002-2338, users should upgrade to the latest versions of Mozilla or Netscape that are not vulnerable.
Is there any workaround for CVE-2002-2338 if upgrading is not possible?
There are no known workarounds for CVE-2002-2338 other than upgrading to a non-vulnerable version.