CVE-2012-0444
published 2012-02-01CVE-2012-0444: Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize…
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.94%
94.1th percentile
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvorbis | < libvorbis 1.3.2-1.2 (bookworm) | libvorbis 1.3.2-1.2 (bookworm) |
| debian | libvorbisidec | < libvorbis 1.3.2-1.2 (bookworm) | libvorbis 1.3.2-1.2 (bookworm) |
| mozilla | firefox | < 3.6.26 | 3.6.26 |
| mozilla | firefox | >= 4.0 < 10.0 | 10.0 |
| mozilla | seamonkey | < 2.7 | 2.7 |
| mozilla | thunderbird | < 3.1.18 | 3.1.18 |
| mozilla | thunderbird | >= 5.0 < 10.0 | 10.0 |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| xiph.org | libvorbis | >= 0 < 1.3.2-1.2 | 1.3.2-1.2 |
| xiph.org | libvorbis | >= 0 < 1.3.2-1.2 | 1.3.2-1.2 |
| xiph.org | libvorbis | >= 0 < 1.3.2-1.2 | 1.3.2-1.2 |
| xiph.org | libvorbis | >= 0 < 1.3.2-1.2 | 1.3.2-1.2 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvorbis vulnerability
vendor_ubuntu·2012-02-20
CVE-2012-0444 libvorbis vulnerability
Title: libvorbis vulnerability
Summary: libvorbis could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libvorbis did not correctly handle certain malformed
ogg files. If a user were tricked into opening a specially crafted ogg file
with an application that uses libvorbis, an attacker could cause a denial
of service or possibly execute arbitrary code with the user's privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-02-17·CVSS 9.3
CVE-2012-0452 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Thunderbird can crash due to memory corruption.
If the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If the user were tricked into opening a specially crafted
file, an attacker could exploit this to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invokin
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-02-08·CVSS 9.3
CVE-2012-0442 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Jesse Ruderman and Bob Clary discovered memory safety issues affecting
Thunderbird. If the user were tricked into opening a specially crafted
page, an attacker could exploit these to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Thunderbird. (CVE-2012-0442)
It was discovered that Thunderbird did not properly handle node removal in
the DOM. If the user were tricked into opening a specially crafted page, an
attacker could exploit this to cause a denial of service via application
crash, or potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2011-3659)
It was discovered that memory corruption c
Ubuntu
Xulrunnner vulnerabilities
vendor_ubuntu·2012-02-08·CVSS 9.3
CVE-2012-0442 [CRITICAL] Xulrunnner vulnerabilities
Title: Xulrunnner vulnerabilities
Summary: Several security issues were fixed in Xulrunner.
Jesse Ruderman and Bob Clary discovered memory safety issues affecting the
Gecko Browser engine. If the user were tricked into opening a specially
crafted page, an attacker could exploit these to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2012-0442)
It was discovered that the Gecko Browser engine did not properly handle
node removal in the DOM. If the user were tricked into opening a specially
crafted page, an attacker could exploit this to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2011-3659)
It was discovered that
Ubuntu
Mozvoikko update
vendor_ubuntu·2012-02-03·CVSS 10.0
CVE-2012-0450 [CRITICAL] Mozvoikko update
Title: Mozvoikko update
Summary: This update provides compatible Mozvoikko packages for the latest Firefox.
USN-1355-1 fixed vulnerabilities in Firefox. This update provides an
updated Mozvoikko package for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially e
Ubuntu
ubufox and webfav update
vendor_ubuntu·2012-02-03·CVSS 10.0
[CRITICAL] ubufox and webfav update
Title: ubufox and webfav update
Summary: This update provides compatible ubufox and webfav packages for the latest
Firefox.
USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated
ubufox and webfav packages for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-02-03·CVSS 10.0
CVE-2012-0450 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If th
Red Hat
Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
vendor_redhat·2012-01-31·CVSS 10.0
CVE-2012-0444 [CRITICAL] Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
Debian
CVE-2012-0444: libvorbis - Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and...
vendor_debian·2012·CVSS 10.0
CVE-2012-0444 [CRITICAL] CVE-2012-0444: libvorbis - Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and...
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
Scope: local
bookworm: resolved (fixed in 1.3.2-1.2)
bullseye: resolved (fixed in 1.3.2-1.2)
forky: resolved (fixed in 1.3.2-1.2)
sid: resolved (fixed in 1.3.2-1.2)
trixie: resolved (fixed in 1.3.2-1.2)
GHSA
GHSA-372v-6w9g-jmh5: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-04
CVE-2012-0444 [HIGH] CWE-119 GHSA-372v-6w9g-jmh5: Mozilla Firefox before 3
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
OSV
CVE-2012-0444: Mozilla Firefox before 3
osv·2012-02-01·CVSS 10.0
CVE-2012-0444 [CRITICAL] CVE-2012-0444: Mozilla Firefox before 3
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07) [fedora-all]
bugzilla·2012-02-15·CVSS 10.0
CVE-2012-0444 [CRITICAL] CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07) [fedora-all]
CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
bugzilla·2012-01-31·CVSS 10.0
CVE-2012-0444 [CRITICAL] CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
CVE-2012-0444 Firefox: Ogg Vorbis Decoding Memory Corruption (MFSA 2012-07)
A memory corruption flaw was found in the way Firefox parsed Ogg Vorbis files. When a malicious Ogg Vorbis file could cause firefox to crash or execute arbitrary code with the permission of the user running firefox.
Reference:
https://bugzilla.mozilla.org/show_bug.cgi?id=719612
Discussion:
Public now via:
http://www.mozilla.org/security/announce/2012/mfsa2012-07.html
---
External References:
http://www.mozilla.org/security/announce/2012/mfsa2012-07.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0079 https://rhn.redhat.com/errata/RHSA-2012-0079.html
---
The following upstream patch fixes this is
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlhttp://secunia.com/advisories/48043http://secunia.com/advisories/48095http://www.debian.org/security/2012/dsa-2400http://www.debian.org/security/2012/dsa-2402http://www.debian.org/security/2012/dsa-2406http://www.mandriva.com/security/advisories?name=MDVSA-2012:013http://www.mozilla.org/security/announce/2012/mfsa2012-07.htmlhttp://www.securityfocus.com/bid/51753http://www.ubuntu.com/usn/USN-1370-1https://bugzilla.mozilla.org/show_bug.cgi?id=719612https://exchange.xforce.ibmcloud.com/vulnerabilities/72858https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14464http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlhttp://secunia.com/advisories/48043http://secunia.com/advisories/48095http://www.debian.org/security/2012/dsa-2400http://www.debian.org/security/2012/dsa-2402http://www.debian.org/security/2012/dsa-2406http://www.mandriva.com/security/advisories?name=MDVSA-2012:013http://www.mozilla.org/security/announce/2012/mfsa2012-07.htmlhttp://www.securityfocus.com/bid/51753http://www.ubuntu.com/usn/USN-1370-1https://bugzilla.mozilla.org/show_bug.cgi?id=719612https://exchange.xforce.ibmcloud.com/vulnerabilities/72858https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14464
2012-02-01
Published