CVE-2007-1362: Input Validation
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1362?
CVE-2007-1362 has a severity level that could lead to denial of service under certain conditions.
How do I fix CVE-2007-1362?
To fix CVE-2007-1362, update Mozilla Firefox to version 1.5.0.12 or later, or 2.0.0.4 or later.
Which versions of Firefox are affected by CVE-2007-1362?
CVE-2007-1362 affects Firefox versions 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4.
Which versions of SeaMonkey are impacted by CVE-2007-1362?
CVE-2007-1362 impacts SeaMonkey versions 1.0.9 and 1.1.2.
Can CVE-2007-1362 be exploited remotely?
Yes, CVE-2007-1362 can be exploited remotely to cause a denial of service.