Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17381 | vdb entry |
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html | vendor advisory |
http://marc.info/?l=bugtraq&m=109900315219363&w=2 | vendor advisory |
http://bugzilla.mozilla.org/show_bug.cgi?id=255067 | vendor advisory |
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3 | |
http://security.gentoo.org/glsa/glsa-200409-26.xml | vendor advisory |
http://www.securityfocus.com/bid/11171 | vdb entry vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA04-261A.html | third party advisory us government resource |
http://marc.info/?l=bugtraq&m=109698896104418&w=2 | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10952 | signature vdb entry |
http://www.kb.cert.org/vuls/id/847200 | third party advisory us government resource |