First published: Wed Apr 06 2005(Updated: )
The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.0.2 | |
Netscape Navigator | =7.2 | |
Mozilla Firefox | =1.0.1 | |
Mozilla Mozilla | =1.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0989 is classified as a moderate severity vulnerability.
To mitigate CVE-2005-0989, users should upgrade to the latest versions of affected software.
CVE-2005-0989 affects Mozilla Suite 1.7.6, Firefox 1.0.1, 1.0.2, and Netscape 7.2.
CVE-2005-0989 can be exploited by remote attackers to read portions of heap memory.
Yes, there are reports of exploitation for CVE-2005-0989, allowing attackers to access sensitive memory data.