S-207: Mozilla Vulnerability in External MIME bodies


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-207: Mozilla Vulnerability in External MIME bodies
# 1  
Old 02-27-2008
S-207: Mozilla Vulnerability in External MIME bodies

There is a heap-based buffer overflow vulnerability in Mozilla mail code which could potentially allow an attacker to run arbitrary code. The risk is MEDIUM. COuld potentially allow an attacker to run arbitrary code. The vulnerability is caused by allocating a buffer that can be three bytes too small in certain cases when viewing an email message with an external MIME body.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. Solaris

command line MIME?

Is there a commandline MIME encoder? standard on solaris 10. (a-la uuencode) (2 Replies)
Discussion started by: bigearsbilly
2 Replies

2. Shell Programming and Scripting

Sending Attachment using MIME in UNIX

Hi, I am using the below code for sending attachment in UNIX but only blank attachment is coming in email even the content is not coming. Please help!!! export CONTENT="${DIR}/${RUN_DATE}_mailbody.txt" export SUBJECT="Search Result for Pattern - ${1}" export ATTACH=${2} ( echo... (9 Replies)
Discussion started by: rajesshh
9 Replies

3. Shell Programming and Scripting

ambigouity on using Mime::Lite?

Hi Everyone, I have a question related to using MIME::Lite module in perl.Below i mentioned code blocks used for sending mail through MIME::Lite. $msg = MIME::Lite -> new ( From => $from, To => $to, Subject... (0 Replies)
Discussion started by: DILEEP410
0 Replies

4. Shell Programming and Scripting

Retrieving File's Mime-type

Alright, so I am trying to use perl (or any other shell scripting language, awk/sed/bash for instance), to retrieve the mime-type of a file. I want to keep it in one file, and most of the modules that are on cpan that check for mime types (Magic), aren't installed on these boxes. Anyone have... (2 Replies)
Discussion started by: Rhije
2 Replies

5. Shell Programming and Scripting

help with mime

hey, i need some help with mime and hebrew. i have a script sending a multipart mime . the problem is that the subject is recived in jibrish. i need to know how to explictly define charset for the subject. i would appericiate any help, thanx in advance, rafi (0 Replies)
Discussion started by: rafiyaari
0 Replies

6. UNIX for Dummies Questions & Answers

mime types

Hi, I am trying to launch an ogg movie from a pdf file which has been produced with pdflatex and \movie {\centerline{\includegraphics {grafiques_xerrades/un_manolo_amb_camera.pdf}}} {hlims_xerrades/XocCumuls.ogg} The switch "externalviewer" makes kpdf launch the default... (5 Replies)
Discussion started by: pau
5 Replies

7. UNIX for Advanced & Expert Users

How to Set Mime type to mailx

I have a problem while sending attachement , it is displying Content into body of mail (Junk Data) instead of attachment (zip format) in Linux, same code is working in Sun Solaris.. I have read query in this site , need to set MIME type to mailx componment. Please help me how to set MIME type..... (1 Reply)
Discussion started by: suneel
1 Replies
Login or Register to Ask a Question
lpweb(1M)																 lpweb(1M)

NAME
lpweb - invokes the HP-UX Printer Management tool SYNOPSIS
[ ] [ ] [ ] DESCRIPTION
The HP-UX Printer Management tool ( ) is used to configure the LP spooling sub-system. It allows the user to view and configure Printers and Print Requests. The tool also allows the user to save and restore spooler configuration. The HP-UX Printer Management tool provides both Web-based and terminal user interface. The Web-based interface is launched through the HP System Management Homepage. Superuser privileges are required to access the HP-UX Printer Management tool. An attempt will be made to connect to a Mozilla/Netscape Web browser running on the X server defined by the DISPLAY environment variable. If a running Mozilla/Netscape client is found, it will be used, otherwise a new Mozilla/Netscape session will be initiated. This will only happen if the Mozilla/Netscape process is running in the same system as that referenced by the DISPLAY variable, unless the -F option is used. Note: By default, the HP-UX Printer Management tool ( ) invokes the Mozilla Web browser. If you want to support any other browser (Net- scape), set the BROWSER environment variable as shown below: The terminal user interface is invoked if any of the following conditions are true: o The command is invoked with the option. o The environment variable is not set. The Web-based interface is launched if all the following conditions are true: o The command is invoked with option. o The environment variable is set. o The command is available on the system. Options recognizes the following options: Forces a client browser to be used in less secure ways. The option forces the client browser to be used or started, even when the X-traffic between the X-server and the Mozilla browser is not secure. Use this option only when you are sure the network traffic between the host where Mozilla is running and the host in the DISPLAY variable is secure. If a privileged user (root) executes the command with the option, a temporary login bypass key is generated. The bypass key enables the user to access the Web interface without having to provide login information again. You can also start the HP-UX Printer Management tool using one of the following methods: o Invoke o Invoke the HP-UX Printers and Plotters Configuration tool Web interface by typing the URL in the address bar of your browser, where hostname is the fully qualified name of the server. o Launch the HP-UX Systems Insight Manager on the server and select the Printer Management tool from Configure -> HP-UX Configuration menu Online Help After the HP-UX Printers and Plotters Configuration tool is started, the online help provides details on how to use the tool. RETURN VALUES
Upon completion, lpweb returns one of the following values: o 0 Successful o 1 An error occurred AUTHOR was developed by Hewlett-Packard Company. SEE ALSO
sam(1M), enable(1), lp(1), lpstat(1), accept(1M), lpsched(1M), lpweb(1M)