[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-0420Date: (C)2008-02-11   (M)2023-12-22


modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1019434
http://www.securityfocus.com/archive/1/488264/100/0/threaded
SUNALERT-238492
BID-27826
SECUNIA-28758
SECUNIA-28839
SECUNIA-29049
SECUNIA-29098
SECUNIA-29167
SECUNIA-30327
SECUNIA-30620
ADV-2008-0627
ADV-2008-1793
FEDORA-2008-2060
FEDORA-2008-2118
GLSA-200805-18
MDVSA-2008:048
USN-576-1
USN-582-1
USN-582-2
firefox-bmp-dos(40606)
firefox-bmp-information-disclosure(40491)
http://browser.netscape.com/releasenotes/
http://www.mozilla.org/security/announce/2008/mfsa2008-07.html
https://bugzilla.mozilla.org/show_bug.cgi?id=408076
oval:org.mitre.oval:def:10119

CPE    80
cpe:/a:mozilla:firefox:1.5.0.4
cpe:/a:mozilla:thunderbird:1.0.2
cpe:/a:mozilla:firefox:1.5.0.2
cpe:/a:mozilla:firefox:1.5.0.1
...
CWE    1
CWE-200
OVAL    1
oval:org.secpod.oval:def:301272

© SecPod Technologies