First published: Fri Oct 04 2002(Updated: )
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla | =0.9.5 | |
Netscape Navigator | =6.2 | |
Opera Browser | =6.0 | |
Opera Browser | =5.12 | |
Mozilla Mozilla | =0.9.7 | |
Netscape Navigator | =6.2.1 | |
Opera Browser | =6.0.1 | |
Mozilla Mozilla | =1.0 | |
Mozilla Mozilla | =0.9.8 | |
Netscape Navigator | =6.2.3 | |
Netscape Navigator | =6.2.2 | |
Mozilla Mozilla | =0.9.6 | |
Mozilla Mozilla | =0.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1091 has a high severity due to the potential for remote attackers to execute arbitrary code.
To fix CVE-2002-1091, update to the latest version of Netscape or Mozilla that does not contain this vulnerability.
Affected software includes Netscape Navigator versions 6.2.3 and earlier, and Mozilla versions 1.0.1 and earlier.
Yes, CVE-2002-1091 can be exploited remotely through a specially crafted GIF image.
CVE-2002-1091 is a heap memory corruption vulnerability.