First published: Tue Oct 26 2004(Updated: )
Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=0.10 | |
Mozilla Gecko | =2004-09-13 | |
Mozilla Firefox | =5.0 | |
Firefox | <=0.10 | |
Mozilla Firefox | =5.0 | |
Mozilla Gecko | =2004-09-13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1639 is classified as a denial of service vulnerability.
CVE-2004-1639 affects Mozilla Firefox versions before 0.10, Mozilla 5.0, and Gecko version 2004-09-13.
To mitigate the risk of CVE-2004-1639, users should upgrade to a version of Mozilla Firefox later than 0.10 or a later version of Mozilla or Gecko.
CVE-2004-1639 involves a denial of service attack that can cause application crashes or excessive memory consumption.
There are no specific workarounds for CVE-2004-1639; the recommended solution is to update the affected software.