CVE-2009-0323: Buffer Overflow
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0323?
The severity of CVE-2009-0323 is considered high due to the potential for remote code execution.
How do I fix CVE-2009-0323?
To fix CVE-2009-0323, update to a version of W3C Amaya that is not affected, preferably 11.0 or later.
What types of vulnerabilities are associated with CVE-2009-0323?
CVE-2009-0323 is associated with multiple stack-based buffer overflows in the Amaya Web Browser.
Which versions of W3C Amaya are affected by CVE-2009-0323?
CVE-2009-0323 affects multiple versions of W3C Amaya, including 10.0, 11.0, and several earlier versions.
Can CVE-2009-0323 be exploited remotely?
Yes, CVE-2009-0323 can be exploited remotely by attackers through crafted input to the web browser.