CVE-2007-5691: Input Validation
Published Oct 29, 2007
·Updated
ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."
Affected Software
1 affected component
Mozilla Firefox=2.0.0.7
Remediation
Patch Available
Event History
Oct 29, 2007
CVE Published
07:46 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5691?
CVE-2007-5691 is classified as a denial of service vulnerability that can cause an application crash.
2
How do I fix CVE-2007-5691?
To mitigate CVE-2007-5691, upgrade to a newer version of Mozilla Firefox, as version 2.0.0.7 is affected.
3
What versions of Mozilla Firefox are affected by CVE-2007-5691?
CVE-2007-5691 specifically affects Mozilla Firefox version 2.0.0.7.
4
What causes the vulnerability CVE-2007-5691?
CVE-2007-5691 is caused by handling crafted replies from remote FTP servers, leading to reading from an invalid pointer.
5
Can CVE-2007-5691 be exploited remotely?
Yes, CVE-2007-5691 can be exploited by remote FTP servers through crafted listing commands.