CVE-2004-0903: Buffer Overflow
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0903?
CVE-2004-0903 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2004-0903?
To address CVE-2004-0903, update your Mozilla Firefox, Mozilla, or Thunderbird applications to the latest versions where the vulnerability has been patched.
What specific software is affected by CVE-2004-0903?
CVE-2004-0903 affects Mozilla Firefox versions before the Preview Release, Mozilla versions prior to 1.7.3, and Thunderbird versions before 0.8.
How can attackers exploit CVE-2004-0903?
Attackers can exploit CVE-2004-0903 by sending malformed VCard attachments that trigger a stack-based buffer overflow when previewed.
What symptoms indicate a system compromise due to CVE-2004-0903?
Indicators of compromise from CVE-2004-0903 may include unexpected system behavior, crashes, or unauthorized program execution after handling specific VCard files.