Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
BID:11171
Info
Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
| Bugtraq ID: | 11171 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0904 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2004 12:00AM |
| Updated: | Aug 05 2010 07:45PM |
| Credit: | Discovery is credited to Daniel Veditz <[email protected]>. |
| Vulnerable: |
Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firebird 0.5 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 |
| Not Vulnerable: |
Mozilla Thunderbird 0.8 Mozilla Firefox Preview Release Mozilla Browser 1.7.3 |
Discussion
Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
Mozilla Browser is reportedly prone to multiple integer overflow vulnerabilities in the image parsing routines. These issues exist due to insufficient boundary checks performed by the application. A remote attacker may cause denial of service conditions in the client or execute arbitrary code to gain unauthorized access to a vulnerable computer.
These vulnerabilities were researched on Mozilla 1.7, however, other versions may be affected as well. Thunderbird 0.7 was also tested.
Mozilla Browser is reportedly prone to multiple integer overflow vulnerabilities in the image parsing routines. These issues exist due to insufficient boundary checks performed by the application. A remote attacker may cause denial of service conditions in the client or execute arbitrary code to gain unauthorized access to a vulnerable computer.
These vulnerabilities were researched on Mozilla 1.7, however, other versions may be affected as well. Thunderbird 0.7 was also tested.
Exploit / POC
Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
Solution:
This issue has been addressed in Mozilla 1.7.3, Firefox Preview
Release, and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.6
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
This issue has been addressed in Mozilla 1.7.3, Firefox Preview
Release, and Thunderbird 0.8.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Thunderbird 0.6
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.1
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 0.8
http://www.mozilla.org/products/thunderbird/releases/
Mozilla Firefox 0.8
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9 rc
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.1
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.2
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.3
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
References
Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities
References:
References:
- Bugzilla Bug 255067 - BMP integer overflow exploits (Daniel Veditz
) - Cisco NX-OS Download Page (Cisco)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2004:486-18 - Updated mozilla packages fix security issues (RedHat)
- VU#847200 - Mozilla contains integer overflows in bitmap image decoder (US-CERT)