CVE-2008-0420
published 2008-02-12CVE-2008-0420: modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly…
PriorityP428critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.22%
80.7th percentile
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
Affected
124 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.11 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-993f-87r7-p76m: Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitma
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2008-0894 [CRITICAL] GHSA-993f-87r7-p76m: Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitma
Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420.
GHSA
GHSA-3m39-96f9-rqqr: Opera before 9
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-6524 [CRITICAL] CWE-200 GHSA-3m39-96f9-rqqr: Opera before 9
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.
GHSA
GHSA-6cgj-54pv-ggm2: modules/libpr0n/decoders/bmp/nsBMPDecoder
ghsa_unreviewed·2022-05-01
CVE-2008-0420 [HIGH] CWE-200 GHSA-6cgj-54pv-ggm2: modules/libpr0n/decoders/bmp/nsBMPDecoder
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
Ubuntu
Thunderbird regression
vendor_ubuntu·2008-03-06·CVSS 7.5
[HIGH] Thunderbird regression
Title: Thunderbird regression
Summary: Thunderbird regression
USN-582-1 fixed several vulnerabilities in Thunderbird. The upstream
fixes were incomplete, and after performing certain actions Thunderbird
would crash due to memory errors. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Thunderbird did not properly set the size of a
buffer when parsing an external-body MIME-type. If a user were to open
a specially crafted email, an attacker could cause a denial of service
via application crash or possibly execute arbitrary code as the user.
(CVE-2008-0304)
Various flaws were discovered in Thunderbird and its JavaScript
engine. By tricking a user into opening a malicious message, an
attacker could execute arbitrary code
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-02-29·CVSS 7.5
CVE-2008-0304 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
It was discovered that Thunderbird did not properly set the size of a
buffer when parsing an external-body MIME-type. If a user were to open
a specially crafted email, an attacker could cause a denial of service
via application crash or possibly execute arbitrary code as the user.
(CVE-2008-0304)
Various flaws were discovered in Thunderbird and its JavaScript
engine. By tricking a user into opening a malicious message, an
attacker could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious message, an attacker could escalate
privileges within Thunderbird, perform cross-site scripting attac
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-02-08·CVSS 9.3
CVE-2008-0412 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the browser and JavaScript engine.
By tricking a user into opening a malicious web page, an attacker
could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)
Flaws were discovered in the file upload form control. A malicious
website could force arbitrary files from the user's computer to be
uploaded without consent. (CVE-2008-0414)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges. (CVE-2008-0415)
Various flaws were discovered in character encoding ha
Red Hat
Mozilla information disclosure flaw
vendor_redhat·2008-02-07·CVSS 9.3
CVE-2008-0420 [CRITICAL] Mozilla information disclosure flaw
Mozilla information disclosure flaw
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
No detection rules found.
http://browser.netscape.com/releasenotes/http://secunia.com/advisories/28758http://secunia.com/advisories/28839http://secunia.com/advisories/29049http://secunia.com/advisories/29098http://secunia.com/advisories/29167http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://securitytracker.com/id?1019434http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:048http://www.mozilla.org/security/announce/2008/mfsa2008-07.htmlhttp://www.securityfocus.com/archive/1/488264/100/0/threadedhttp://www.securityfocus.com/bid/27826http://www.ubuntu.com/usn/usn-582-1http://www.ubuntu.com/usn/usn-582-2http://www.vupen.com/english/advisories/2008/0627/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408076https://exchange.xforce.ibmcloud.com/vulnerabilities/40491https://exchange.xforce.ibmcloud.com/vulnerabilities/40606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10119https://usn.ubuntu.com/576-1/https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.htmlhttp://browser.netscape.com/releasenotes/http://secunia.com/advisories/28758http://secunia.com/advisories/28839http://secunia.com/advisories/29049http://secunia.com/advisories/29098http://secunia.com/advisories/29167http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://securitytracker.com/id?1019434http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:048http://www.mozilla.org/security/announce/2008/mfsa2008-07.htmlhttp://www.securityfocus.com/archive/1/488264/100/0/threadedhttp://www.securityfocus.com/bid/27826http://www.ubuntu.com/usn/usn-582-1http://www.ubuntu.com/usn/usn-582-2http://www.vupen.com/english/advisories/2008/0627/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408076https://exchange.xforce.ibmcloud.com/vulnerabilities/40491https://exchange.xforce.ibmcloud.com/vulnerabilities/40606https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10119https://usn.ubuntu.com/576-1/https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html
2008-02-12
Published