CVE-2008-0420: Infoleak
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0420?
CVE-2008-0420 is considered a moderate severity vulnerability due to its potential to expose uninitialized memory content.
How do I fix CVE-2008-0420?
The recommended fix for CVE-2008-0420 is to upgrade to Mozilla Firefox version 2.0.0.12 or later, Thunderbird version 2.0.0.12 or later, and SeaMonkey version 1.1.8 or later.
What products are affected by CVE-2008-0420?
CVE-2008-0420 affects various versions of Mozilla Firefox, Thunderbird, and SeaMonkey prior to specific updates.
What type of attack can exploit CVE-2008-0420?
CVE-2008-0420 can be exploited by remote attackers to read portions of uninitialized memory through crafted image files.
When was CVE-2008-0420 disclosed?
CVE-2008-0420 was disclosed in January 2008, highlighting a vulnerability in earlier versions of Mozilla products.