https://bugzilla.novell.com/show_bug.cgi?id=363574
User thomas@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=363574#c4
--- Comment #4 from Thomas Biege 2008-02-26 05:07:22 MST ---
CVE-2008-0420
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before
2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not
properly perform certain calculations related to the mColors table, which
allows remote attackers to read portions of memory uninitialized via a crafted
8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as
demonstrated using a CANVAS element; or cause a denial of service (application
crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read.
NOTE: the initial public reports stated that this affected Firefox in Ubuntu
6.06 through 7.10.
CVE-2007-6524
Opera before 9.25 allows remote attackers to obtain potentially sensitive
memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS
element and JavaScript in an HTML document for copying these contents from 9.50
beta, a related issue to CVE-2008-0420.
--
Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.