SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#722244

Mozilla products vulnerable to heap overflow via miscalculated size during conversion of an image

Overview

A vulnerability exists in Mozilla products that may allow a remote attacker to execute arbitrary code or cause a denial of service.

I. Description

Mozilla products contain a vulnerability in the CSS cursor property on Microsoft Windows that may result in a crash when handling malicious images. According to the Mozilla Foundation Security Advisory 2006-69:

    A miscalculated size during conversion of the image to a Windows bitmap can result in a heap buffer overflow which could be used to compromise the victim's computer.


Mozilla also states that this flaw affects both Firefox 2 and Firefox 1.5 but not the earlier Firefox 1.0 or Mozilla Suite products.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service.

III. Solution

Apply an update

According to the Mozilla Foundation Security Advisory 2006-69, this vulnerability is addressed in Firefox 2.0.0.1, Firefox 1.5.0.9, Thunderbird 1.5.0.9, and SeaMonkey 1.0.7.

Systems Affected

VendorStatusDate Updated
Gentoo LinuxVulnerable18-Jan-2007
Mandriva, Inc.Vulnerable18-Jan-2007
MozillaVulnerable21-Dec-2006
SUSE LinuxVulnerable18-Jan-2007

References


http://www.mozilla.org/security/announce/2006/mfsa2006-69.html
https://bugzilla.mozilla.org/show_bug.cgi?id=353553
http://secunia.com/advisories/23591/
http://secunia.com/advisories/23598/
http://secunia.com/advisories/23439/
http://secunia.com/advisories/23514/
http://secunia.com/advisories/23545/
http://secunia.com/advisories/23601/
http://secunia.com/advisories/23614/
http://secunia.com/advisories/23618/
http://secunia.com/advisories/23692/
http://www.securityfocus.com/bid/21668

Credit

This issue is addressed in Mozilla Foundation Security Advisory 2006-69. Mozilla credits Frederik Reiss with providing information about this issue.

This document was written by Chris Taschner.

Other Information

Date Public12/19/2006
Date First Published01/18/2007 10:54:47 AM
Date Last Updated01/18/2007
CERT Advisory 
CVE NameCVE-2006-6500
US-CERT Technical Alerts 
Metric12.15
Document Revision21

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader