First published: Wed Aug 29 2012(Updated: )
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <15.0 | |
Firefox | >=10.0<10.0.7 | |
Mozilla SeaMonkey | <2.12 | |
Thunderbird | <15.0 | |
Mozilla Thunderbird | >=10.0<10.0.7 | |
SUSE Linux | =12.2 | |
SUSE Linux Enterprise Desktop | =10-sp4 | |
SUSE Linux Enterprise Desktop | =11-sp2 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Software Development Kit | =11-sp2 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server EUS | =6.3 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =6.3 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Ubuntu | =10.04 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Debian | =6.0 | |
Debian | =7.0 | |
Firefox ESR | >=10.0<10.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3972 has been classified as a high severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2012-3972, users should update their affected Mozilla applications to the latest versions where the vulnerability has been patched.
CVE-2012-3972 affects Mozilla Firefox versions before 15.0, Thunderbird versions before 15.0, and SeaMonkey versions before 2.12, along with specific versions of the ESR editions.
The impact of CVE-2012-3972 allows remote attackers to potentially gain access to sensitive information.
While CVE-2012-3972 is an older vulnerability, it remains relevant for users still operating on unsupported or outdated versions of affected software.