First published: Thu Mar 24 2005(Updated: )
Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | =0.6 | |
Firefox | =0.8 | |
Thunderbird | =0.7.2 | |
Thunderbird | =0.3 | |
Mozilla Firefox | =1.7-alpha | |
Thunderbird | =0.2 | |
Mozilla Firefox | =1.7-rc1 | |
Mozilla Firefox | =1.5-rc2 | |
Mozilla Firefox | =1.7 | |
Firefox | =0.9.1 | |
Mozilla Firefox | =1.7.5 | |
Firefox | =0.10.1 | |
Thunderbird | =1.0 | |
Firefox | =0.9 | |
Thunderbird | =1.0.1 | |
Mozilla Firefox | =1.6-beta | |
Mozilla Firefox | =1.4.1 | |
Mozilla Firefox | =1.5-alpha | |
Mozilla Firefox | =1.5-rc1 | |
Mozilla Firefox | =1.3 | |
Firefox | =1.0 | |
Mozilla Firefox | =1.7-beta | |
Firefox | =1.0.1 | |
Mozilla Firefox | =1.4 | |
Mozilla Firefox | =1.5 | |
Thunderbird | =0.5 | |
Thunderbird | =0.9 | |
Mozilla Firefox | =1.7.1 | |
Thunderbird | =0.7.3 | |
Firefox | =0.9.3 | |
Mozilla Firefox | =1.4-alpha | |
Thunderbird | =0.4 | |
Thunderbird | =0.7 | |
Mozilla Firefox | =1.5.1 | |
Firefox | =0.9.2 | |
Mozilla Firefox | =1.7.2 | |
Thunderbird | =0.1 | |
Firefox | =0.9-rc | |
Mozilla Firefox | =1.7-rc3 | |
Thunderbird | =0.7.1 | |
Thunderbird | =0.8 | |
Mozilla Firefox | =1.7-rc2 | |
Firefox | =0.10 | |
Mozilla Firefox | =1.7.3 | |
Mozilla Firefox | =1.6-alpha | |
Mozilla Firefox | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0399 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code.
To fix CVE-2005-0399, upgrade to the latest version of Firefox, Thunderbird, or Mozilla that addresses the vulnerability.
CVE-2005-0399 affects multiple versions of Mozilla Firefox, Mozilla, and Thunderbird prior to their respective patches.
A heap-based buffer overflow occurs when an application writes more data to a block of memory on the heap than it was allocated, which can allow attackers to manipulate the program's execution.
Yes, simply viewing a crafted GIF image in an affected application can lead to exploitation via CVE-2005-0399.