CVE-2008-0420
Published Feb 12, 2008
Last updated 6 years ago
Overview
- Description
- modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3E4F934-1CC7-475C-B425-BEEF29AED912", "versionEndIncluding": "2.0.0.11" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C7AA88B-638A-451A-B235-A1A1444BE417" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C01AD7C-8470-47AB-B8AE-670E3A381E89" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E43F2F1-9252-4B44-8A61-D05305915A5F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3BB9D48B-DC7B-4D92-BB26-B6DE629A2506" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A360D595-A829-4DDE-932E-9995626917E5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E9B5349-FAA7-4CDA-9533-1AD1ACDFAC4E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07243837-C353-4C25-A5B1-4DA32807E97D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B832C034-F793-415F-BFC8-D97A18BA6BC7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83CD1A13-66CB-49CC-BD84-5D8334DB774A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93C142C5-3A85-432B-80D6-2E7B1B4694F4" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2434FCE7-A50B-4527-9970-C7224B31141C" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "429ECA02-DBCD-45FB-942C-CA4BC1BC8A72" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5F0DC80-5473-465C-9D7F-9589F1B78E12" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "567FF916-7DE0-403C-8528-7931A43E0D18" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A545A77-2198-4685-A87F-E0F2DAECECF6" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "438AACF8-006F-4522-853F-30DBBABD8C15" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EDBAC37-9D08-44D1-B279-BC6ACF126CAF" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "834BB391-5EB5-43A8-980A-D305EDAE6FA7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F2938F2-A801-45E5-8E06-BE03DE03C8A7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABB88E86-6E83-4A59-9266-8B98AA91774D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D6BF5B1-86D1-47FE-9D9C-735718F94874" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84D15CE0-69DF-4EFD-801E-96A4D6AABEDB" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2F38886-C25A-4C6B-93E7-36461405BA99" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE8E5194-7B34-4802-BDA6-6A86EB5EDE05" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FABA5F56-99F7-4F8F-9CC1-5B0B2EB72922" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A524A94E-F19B-42B9-AA8E-171751C339AA" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F71436CF-F756-44E0-8E69-6951F6B3E54A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "824369CF-00A0-434E-94BC-71CA1317012C" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3487FA64-BE04-42CA-861E-3DAC097D7D32" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3D956DC-C73B-439F-8D79-8239207CC76F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57E2C7E7-56C0-466C-BB08-5EB43922C4F9" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4105171B-9C90-4ABF-B220-A35E7BA9EE40" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20985549-DB24-4B69-9D40-208A47AE658E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43A13026-416F-4308-8A1B-E989BD769E12" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "612B015E-9F96-4CE6-83E4-23848FD609E5" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DBB527B8-3829-4C2E-8A46-F4D4EA5C5060", "versionEndIncluding": "1.1.7" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09E18FC0-0C8C-4FA1-85B9-B868D00F002F" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A97B6E1-EABA-4977-A3FC-64DF0392AA95" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB01A97F-ACE1-4A99-8939-6DF8FE5B5E8E" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6521C877-63C9-4B6E-9FC9-1263FFBB7950" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D949DF0A-CBC2-40E1-AE6C-60E6F58D2481" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C5CDA57-1A50-4EDB-80E2-D3EBB44EA653" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3104343E-93B6-4D4A-BC95-ED9F7E91FB6A" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "381313EF-DF84-4F66-9962-DE8F45029D79" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0228476-14E4-443C-BBAE-2C9CD8594DC0" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A803A500-DCE2-44FC-ABEB-A90A1D39D85C" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "022274DE-5251-49C9-B6E5-1D8CEDC34E7D" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9F84CB7-93F7-4912-BC87-497867B96491" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8992E9C6-09B3-492E-B7DA-899D5238EC18" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D58B704B-F06E-44C1-BBD1-A090D1E6583A" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40270FBD-744A-49D9-9FFA-1DCD897210D7" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20E01097-F60A-4FB2-BA47-84A267EE87D6" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E6D7528-E591-48A6-8165-BE42F8EBF6B6" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25E3F549-B010-49E4-B8F6-B22727D57AA6", "versionEndIncluding": "2.0.0.11" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0618BD26-0EF5-4774-9131-B5ABD4CD302A" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61E565E5-286D-4A68-B085-5659DFE59A9C" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E2A68B4-9101-4AC5-9E82-EEB5A5405541" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDA6C390-9BA7-4355-8C0A-CD68FF6AC236" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5263F879-9B90-4582-B677-F133DEBE5259" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C256B73C-9ABC-43D4-8C57-09161BC9F923" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "055D1044-9FC5-45AA-8407-649E96C5AFE3" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C4DB0BB-BFD7-4E7A-B3EF-9C5422602216" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFC390CB-774C-47BE-95C3-059943A9E645" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B71DE7AC-553B-4524-8B33-5605518449EB" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41AE4644-2D23-43EA-ABDA-7BE60EFD1EFF" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FB87608-0DF8-4729-95C5-CFA386AB3AC2" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C99BAF7-B48E-4402-B2BF-EB07235E402E" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0ADE8D7-B3C3-4490-9CD5-0263BBA75D28" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C86FD617-E4FE-4F85-AAA4-4F968A9DEC9F" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E28672BA-E3C2-40C3-80E1-95B7CDD089E2" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6654EC3-BED6-4D6D-9B7F-DF4CC8E464BB" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "581615BB-C781-42CA-836E-0E0EAB8C4504" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "257F43FA-D22C-4BF0-A02E-261A54142BCB" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:1.5.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C8D63F5-78D5-4F7B-B15A-2C15FC405E27" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:2.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFC60781-766B-4B9C-B68D-45D51C5E5D20" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:2.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC7EAB8D-CA40-4C29-99DF-24FF1753BCF9" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:2.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C9218A9-DA27-436A-AC93-F465FC14ECF3" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:2.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E66503D7-72CB-42A5-8C85-D9579EF2C0A5" }, { "criteria": "cpe:2.3:a:mozilla:thunderbird:2.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B373B409-0939-4707-99F1-95B121BFF7FC" } ], "operator": "OR" } ] } ]