Mozilla Browser 1.7.x - Non-ASCII Hostname Heap Overflow
Author: Mats Palmgren & Gael Delalleau
type: dos
platform: multiple
port:
date_added: 2004-09-14
date_updated: 2013-03-05
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/11169/info
Mozilla is prone to a remotely exploitable heap overflow that is exposed when the browser handles non-ASCII characters in URIs.
This issue could be exploited by enticing a user to open a hyperlink that references a malicious URI. Successful exploitation will allow execution of arbitrary code in the context of the client user.
http://é------------------------------------------------aaaabbbb-----/
http://é------------------------------------------------þßý-----/
http://é------------------------------------------------aaaa$ðý-----/