CVE-2012-0447: Infoleak
Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0447?
CVE-2012-0447 has been rated as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2012-0447?
To mitigate CVE-2012-0447, users should upgrade to the latest version of Mozilla Firefox, Thunderbird, or SeaMonkey that resolves the vulnerability.
Which versions of Mozilla software are affected by CVE-2012-0447?
CVE-2012-0447 affects Mozilla Firefox versions 4.x to 9.0, Thunderbird versions 5.0 to 9.0, and SeaMonkey versions prior to 2.7.
What type of vulnerability is CVE-2012-0447 classified as?
CVE-2012-0447 is classified as an information disclosure vulnerability.
Can CVE-2012-0447 be exploited remotely?
Yes, CVE-2012-0447 can be exploited by remote attackers through specially crafted images.