CVE-2005-2701: Buffer Overflow
Published Sep 23, 2005
·Updated
Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.
Affected Software
12 affected components
Mozilla Firefox<=1.0.6
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Firefox=1.0.3
Mozilla Firefox=1.0.4
Mozilla Firefox=1.0.5
Mozilla Mozilla Suite<=1.7.11
Mozilla Mozilla Suite=1.7.6
Mozilla Mozilla Suite=1.7.7
Mozilla Mozilla Suite=1.7.8
Mozilla Mozilla Suite=1.7.10
Event History
Sep 23, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2701?
CVE-2005-2701 has been classified as a critical vulnerability due to its potential for remote code execution.
2
What versions of Firefox are affected by CVE-2005-2701?
CVE-2005-2701 affects all Firefox versions prior to 1.0.7.
3
How do I fix CVE-2005-2701?
To mitigate CVE-2005-2701, upgrade Firefox or Mozilla Suite to the latest versions that include security patches.
4
What type of attack does CVE-2005-2701 enable?
CVE-2005-2701 allows remote attackers to execute arbitrary code by exploiting a heap-based buffer overflow.
5
Can CVE-2005-2701 be exploited through images?
Yes, CVE-2005-2701 can be exploited via specially crafted XBM image files.