CVE-2008-0017: Buffer Overflow
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0017?
CVE-2008-0017 is classified as a high severity vulnerability due to its potential to cause a denial of service and possible arbitrary code execution.
How do I fix CVE-2008-0017?
To fix CVE-2008-0017, update your Firefox or SeaMonkey browser to the latest version available that addresses this vulnerability.
What versions are affected by CVE-2008-0017?
CVE-2008-0017 affects Firefox versions before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey before 1.1.13.
Can CVE-2008-0017 be exploited remotely?
Yes, CVE-2008-0017 can be exploited remotely by attackers to crash affected browsers or potentially execute arbitrary code.
Is there a specific platform that CVE-2008-0017 affects?
CVE-2008-0017 affects various operating systems, including multiple versions of Ubuntu Linux and Debian Linux, alongside specific versions of Firefox and SeaMonkey.