FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0399

This CVE name corresponds to:

Entered Topic
2005-03-24 mozilla -- heap buffer overflow in GIF image processing

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0399
Phase Assigned(20050214)

Description

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.

References

Source Reference
ISS 20050323 Mozilla Foundation GIF Overflow
CONFIRM http://www.mozilla.org/security/announce/mfsa2005-30.html
MISC https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877
GENTOO GLSA-200503-30
HP HPSBUX01133
HP SSRT5940
REDHAT RHSA-2005:323
REDHAT RHSA-2005:335
REDHAT RHSA-2005:336
REDHAT RHSA-2005:337
SCO SCOSA-2005.49
SUSE SUSE-SA:2006:022
SUSE SUSE-SA:2006:004
CERT-VN VU#557948
CIAC P-160
BID 12881
BID 15495
OVAL oval:org.mitre.oval:def:11377
VUPEN ADV-2005-0296
OVAL oval:org.mitre.oval:def:100028
SECUNIA 14654
SECUNIA 19823
XF gif-extension-overflow(19269)