CVE Database
/

CVE-2008-0420

Back to search

CVE-2008-0420

Published: Feb 12, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-582-2
vendor-advisory
x_refsource_UBUNTU
FEDORA-2008-2118
vendor-advisory
x_refsource_FEDORA
FEDORA-2008-2060
vendor-advisory
x_refsource_FEDORA
30620
third-party-advisory
x_refsource_SECUNIA
29049
third-party-advisory
x_refsource_SECUNIA
USN-582-1
vendor-advisory
x_refsource_UBUNTU
29167
third-party-advisory
x_refsource_SECUNIA
30327
third-party-advisory
x_refsource_SECUNIA
238492
vendor-advisory
x_refsource_SUNALERT
ADV-2008-1793
vdb-entry
x_refsource_VUPEN
27826
vdb-entry
x_refsource_BID
firefox-bmp-dos(40606)
vdb-entry
x_refsource_XF
1019434
vdb-entry
x_refsource_SECTRACK
oval:org.mitre.oval:def:10119
vdb-entry
signature
x_refsource_OVAL
ADV-2008-0627
vdb-entry
x_refsource_VUPEN
GLSA-200805-18
vendor-advisory
x_refsource_GENTOO
28758
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:048
vendor-advisory
x_refsource_MANDRIVA
29098
third-party-advisory
x_refsource_SECUNIA
28839
third-party-advisory
x_refsource_SECUNIA
USN-576-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2008-0420 - Security Vulnerability | QwikSec