CVE-2012-1960Sensitive Information Exposure in Mozilla Seamonkey

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 14

Description

The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/seamonkey2.10+49
NVDmozilla/firefox16 versions+15
NVDmozilla/thunderbird17 versions+16

🔴Vulnerability Details

2
GHSA
GHSA-6mxc-p6wr-x8pc: The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 42022-05-14
CVEList
CVE-2012-1960: The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 42012-07-18

📋Vendor Advisories

4
Ubuntu
ubufox update2012-07-18
Ubuntu
Firefox vulnerabilities2012-07-17
Ubuntu
Thunderbird vulnerabilities2012-07-17
Red Hat
Mozilla: Out of bounds read in QCMS (MFSA 2012-50)2012-07-17

💬Community

1
Bugzilla
CVE-2012-1960 Mozilla: Out of bounds read in QCMS (MFSA 2012-50)2012-07-14
CVE-2012-1960 — Sensitive Information Exposure | cvebase