CVE-2009-2463: Buffer Overflow
Multiple integer overflows in the (1) PLBase64Decode and (2) PLBase64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2463?
CVE-2009-2463 has been classified as a moderate severity vulnerability due to the potential for denial of service caused by memory corruption.
How do I fix CVE-2009-2463?
To fix CVE-2009-2463, update your Mozilla Firefox, Thunderbird, or SeaMonkey applications to versions that are patched against this vulnerability.
What applications are affected by CVE-2009-2463?
CVE-2009-2463 affects multiple versions of Mozilla Firefox, Thunderbird, and SeaMonkey prior to their respective patched releases.
What types of attacks can exploit CVE-2009-2463?
CVE-2009-2463 can be exploited by remote attackers to trigger integer overflows, leading to application crashes and denial of service.
Is CVE-2009-2463 still a risk if I use an updated version?
No, if you have updated to a non-vulnerable version of the affected applications, CVE-2009-2463 should no longer pose a risk.