vendor:
Sunbird
by:
Maksymilian Arciemowicz and sp3x
7.5
CVSS
HIGH
Array Overrun
199
CWE
Product Name: Sunbird
Affected Version From: Sunbird 0.9
Affected Version To: Prior versions may also be affected.
Patch Exists: YES
Related CWE: CVE-2009-0689
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0153/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0154/, https://www.rapid7.com/db/vulnerabilities/apple-osx-libsystem-cve-2009-0689/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0312/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1601/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0311/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-0689/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2009-0689/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-4b3a7e70-afce-11e5-b864-14dae9d210b8/, https://www.rapid7.com/db/vulnerabilities/mfsa2009-59-cve-2009-0689/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-0689/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=46271, https://www.infosecmatter.com/nessus-plugin-library/?id=63923, https://www.infosecmatter.com/nessus-plugin-library/?id=42890, https://www.infosecmatter.com/nessus-plugin-library/?id=42288, https://www.infosecmatter.com/nessus-plugin-library/?id=45372, https://www.infosecmatter.com/nessus-plugin-library/?id=42287, https://www.infosecmatter.com/nessus-plugin-library/?id=45373, https://www.infosecmatter.com/nessus-plugin-library/?id=67948, https://www.infosecmatter.com/nessus-plugin-library/?id=43379, https://www.infosecmatter.com/nessus-plugin-library/?id=42306
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Cross-platform
2009
Sunbird 0.9 Array Overrun (code execution)
Mozilla Sunbird is a cross-platform calendar application, built upon Mozilla Toolkit. The main problem exist in dtoa implementation. Sunbird has the same dtoa as Firefox, etc. Problem exist in js3250.dll (version 4.0.0 - Netscape 32-bit JavaScript Module) DLL library and it is the same like SREASONRES:20090625. We can create any number of float, which will overwrite the memory. In Kmax has defined 15. Functions in dtoa, don't checks Kmax limit, and it is possible to call 16>test.ics'); print myfile $header.$s.$expl.$footer;
Mitigation:
Fix for SREASONRES:20090625, used by openbsd was not good. More information about fix for openbsd and similars SREASONRES:20091030.