PT-2012-6331 · Mozilla+3 · Firefox+5

Regenrecht

·

Published

1970-01-01

·

Updated

2024-12-12

·

CVE-2012-0444

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 4.x through 9.0 Mozilla Firefox version 3.6.26 and earlier Thunderbird versions 5.0 through 9.0 Thunderbird version 3.1.18 and earlier SeaMonkey version 2.7 and earlier
Description The issue is related to the improper initialization of nsChildView data structures, which can be exploited by remote attackers using a crafted Ogg Vorbis file. This can lead to a denial of service, memory corruption, and application crash, or possibly the execution of arbitrary code. The vulnerability can be exploited remotely and may affect the confidentiality, integrity, and availability of protected information.
Recommendations For Mozilla Firefox versions 4.x through 9.0, update to a version later than 9.0. For Mozilla Firefox version 3.6.26 and earlier, update to a version later than 3.6.26. For Thunderbird versions 5.0 through 9.0, update to a version later than 9.0. For Thunderbird version 3.1.18 and earlier, update to a version later than 3.1.18. For SeaMonkey version 2.7 and earlier, update to a version later than 2.7.

Exploit

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04026
BDU:2015-04387
BDU:2015-04388
BDU:2015-04389
BDU:2015-04390
CESA-2012_0079
CESA-2012_0136
CVE-2012-0444
DSA-2400-1
DSA-2402-1
DSA-2406-1
DSA-2412-1
OPENSUSE-SU-2012_0319-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10024-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10218-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2012:0079
RHSA-2012:0136
RHSA-2012_0079
RHSA-2012_0136
SUSE-SU-2012_0326-1
ZDI-12-059

Affected Products

Centos
Firefox
Red Hat
Seamonkey
Suse
Thunderbird