Mozilla · Firefox · CVE-2012-0447
**Name of the Vulnerable Software and Affected Versions**
Mozilla Firefox versions 4.x through 9.0
Thunderbird versions 5.0 through 9.0
SeaMonkey versions prior to 2.7
**Description**
The issue allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image, due to improper initialization of data for image/vnd.microsoft.icon images.
**Recommendations**
For Mozilla Firefox versions 4.x through 9.0, update to a version that properly initializes data for image/vnd.microsoft.icon images.
For Thunderbird versions 5.0 through 9.0, update to a version that properly initializes data for image/vnd.microsoft.icon images.
For SeaMonkey versions prior to 2.7, update to version 2.7 or later.