CVE-2008-4070: Buffer Overflow
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4070?
CVE-2008-4070 is rated as moderate in severity due to its potential to cause denial of service or execute arbitrary code.
How do I fix CVE-2008-4070?
To fix CVE-2008-4070, update Mozilla Thunderbird to version 2.0.0.17 or later, or SeaMonkey to version 1.1.12 or later.
What types of attacks can exploit CVE-2008-4070?
CVE-2008-4070 can be exploited through specially crafted news articles with long headers sent to vulnerable applications.
Which software versions are affected by CVE-2008-4070?
CVE-2008-4070 affects Mozilla Thunderbird versions prior to 2.0.0.17 and SeaMonkey versions prior to 1.1.12.
What are the consequences of an exploit of CVE-2008-4070?
Exploiting CVE-2008-4070 can lead to application crashes or potentially allow attackers to execute arbitrary code on the target system.