Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
BID:12881
Info
Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
| Bugtraq ID: | 12881 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0399 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2005 12:00AM |
| Updated: | Feb 28 2007 12:46AM |
| Credit: | Discovery is credited to Mark Dowd of ISS X-Force. Juha-Matti Laurio confirmed that this vulnerability also affects Netscape 7.2 and 6.2.3 and the K-Meleon browser. |
| Vulnerable: |
SGI ProPack 3.0 SCO Unixware 7.1.4 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux Advanced Work Station 2.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Netscape Netscape 6.2.3 Netscape Netscape 6.2.2 Netscape Netscape 6.2.1 Mozilla Thunderbird 1.0.1 Mozilla Thunderbird 1.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 rc2 Mozilla Browser 1.7 rc1 Mozilla Browser 1.7 beta Mozilla Browser 1.7 alpha Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5.1 Mozilla Browser 1.5 Mozilla Browser 1.4.4 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 Mozilla Browser 0.9.48 Mozilla Browser 0.9.35 Mozilla Browser 0.9.9 Mozilla Browser 0.9.8 Mozilla Browser 0.9.7 Mozilla Browser 0.9.6 Mozilla Browser 0.9.5 Mozilla Browser 0.9.4 .1 Mozilla Browser 0.9.4 Mozilla Browser 0.9.3 Mozilla Browser 0.9.2 .1 Mozilla Browser 0.9.2 Mozilla Browser 0.8 Mozilla Browser M16 Mozilla Browser M15 K-Meleon K-Meleon 0.9 K-Meleon K-Meleon 0.8.2 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Thunderbird 1.0.2 Mozilla Firefox 1.0.2 Mozilla Browser 1.8 Alpha 4 Mozilla Browser 1.8 Alpha 3 Mozilla Browser 1.8 Alpha 2 Mozilla Browser 1.8 Alpha 1 Mozilla Browser 1.7.6 |
Discussion
Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
Multiple Mozilla products are affected by a remote heap-overflow vulnerability. This issue affects the GIF image processing library used by Mozilla Firefox, Mozilla Browser, and Mozilla Thunderbird Mail client.
A successful attack can result in arbitrary code execution and in unauthorized access to the affected computer. Arbitrary code execution will take place in the context of a user running a vulnerable application.
*Update: K-Meleon, which is based on the Mozilla Gecko-code base, is also prone to this issue.
Multiple Mozilla products are affected by a remote heap-overflow vulnerability. This issue affects the GIF image processing library used by Mozilla Firefox, Mozilla Browser, and Mozilla Thunderbird Mail client.
A successful attack can result in arbitrary code execution and in unauthorized access to the affected computer. Arbitrary code execution will take place in the context of a user running a vulnerable application.
*Update: K-Meleon, which is based on the Mozilla Gecko-code base, is also prone to this issue.
Exploit / POC
Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
A proof-of-concept exploit is available:
A proof-of-concept exploit is available:
Solution / Fix
Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
Solution:
Mozilla has released an advisory (MFSA 2005-30) to address this issue in affected applications.
Please see the referenced advisories for more information.
Mozilla Browser M15
Redhat Fedora Core2
Mozilla Browser M16
Mozilla Firefox 0.10
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Browser 0.8
Mozilla Thunderbird 0.8
Mozilla Firefox 0.9
Mozilla Thunderbird 0.9
Mozilla Firefox 0.9.1
Mozilla Browser 0.9.2 .1
Mozilla Firefox 0.9.2
Mozilla Browser 0.9.2
Mozilla Browser 0.9.3
Mozilla Firefox 0.9.3
Mozilla Browser 0.9.35
Mozilla Browser 0.9.4
Mozilla Browser 0.9.48
Mozilla Browser 0.9.5
Mozilla Browser 0.9.7
Mozilla Browser 0.9.8
Mozilla Browser 0.9.9
Mozilla Browser 1.0
Mozilla Firefox 1.0
Mozilla Browser 1.0 RC1
Mozilla Firefox 1.0.1
Mozilla Thunderbird 1.0.1
Mozilla Browser 1.0.1
Mozilla Browser 1.1
Mozilla Browser 1.1 Alpha
Mozilla Browser 1.1 Beta
Mozilla Browser 1.2 Alpha
Mozilla Browser 1.2
Mozilla Browser 1.2 Beta
Mozilla Browser 1.2.1
Mozilla Browser 1.4
Mozilla Browser 1.4 a
Mozilla Browser 1.4.1
Mozilla Browser 1.4.2
Mozilla Browser 1.5
Mozilla Browser 1.5.1
Mozilla Browser 1.7 rc1
Mozilla Browser 1.7
Mozilla Browser 1.7 rc2
Mozilla Browser 1.7 alpha
Mozilla Browser 1.7 beta
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Mozilla Browser 1.7.3
Mozilla Browser 1.7.4
S.u.S.E. Linux Professional 10.0
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.3
Solution:
Mozilla has released an advisory (MFSA 2005-30) to address this issue in affected applications.
Please see the referenced advisories for more information.
Mozilla Browser M15
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Redhat Fedora Core2
-
Fedora devhelp-0.9.1-0.2.5.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-0.9.1-0.2.5.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-debuginfo-0.9.1-0.2.5.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-debuginfo-0.9.1-0.2.5.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-devel-0.9.1-0.2.5.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora devhelp-devel-0.9.1-0.2.5.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-1.2.10-0.2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-1.2.10-0.2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-debuginfo-1.2.10-0.2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora epiphany-debuginfo-1.2.10-0.2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Mozilla Browser M16
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 1.0.2
http://download.mozilla.org/?product=thunderbird-1.0.2&os=win&lang=en- US
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 1.0.2
http://download.mozilla.org/?product=thunderbird-1.0.2&os=win&lang=en- US
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Browser 0.8
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Thunderbird 0.8
-
Fedora thunderbird-1.0.2-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-1.0.2-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-debuginfo-1.0.2-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-debuginfo-1.0.2-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mozilla Thunderbird 1.0.2
http://download.mozilla.org/?product=thunderbird-1.0.2&os=win&lang=en- US
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.9
-
Mozilla Thunderbird 1.0.2
http://download.mozilla.org/?product=thunderbird-1.0.2&os=win&lang=en- US
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Browser 0.9.2 .1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Browser 0.9.2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.3
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Browser 0.9.35
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.4
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.48
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.5
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.7
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.8
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 0.9.9
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/ -
Red Hat Fedora galeon-1.2.14-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/galeon-1.2.14 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.7 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.7 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-chat- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-devel -1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-dom-i nspector-1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-1.7.7 -0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-mail- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr- 1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nspr- devel-1.7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-1 .7.7-0.73.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-0.73.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/7.3/updates/i386/mozilla-nss-d evel-1.7.7-0.73.2.legacy.i386.rpm
Mozilla Browser 1.0
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Firefox 1.0
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Browser 1.0 RC1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Firefox 1.0.1
-
Mozilla Firefox 1.0.2
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 1.0.1
-
Mozilla Thunderbird 1.0.2
http://download.mozilla.org/?product=thunderbird-1.0.2&os=win&lang=en- US
Mozilla Browser 1.0.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.1 Alpha
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.1 Beta
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.2 Alpha
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.2 Beta
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.2.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/ -
Red Hat Fedora galeon-1.2.14-0.90.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/galeon-1.2.14-0 .90.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-1.7.7-0 .90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-chat-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-devel-1 .7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-dom-ins pector-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-js-debu gger-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-mail-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-1. 7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-de vel-1.7.7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-1.7 .7-0.90.1.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-0.90.1.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-dev el-1.7.7-0.90.1.legacy.i386.rpm
Mozilla Browser 1.4
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/ -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/g aim-1.2.0-i486-1.tgz -
Slackware mozilla-1.4.4-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-1.4.4-i486-1.tgz -
Slackware mozilla-plugins-1.4.4-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-plugins-1.4.4-noarch-1.tgz
Mozilla Browser 1.4 a
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.4.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/ -
Red Hat Fedora epiphany-1.0.8-1.fc1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/epiphany-1.0.8- 1.fc1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.7.7-1 .1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-chat-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1 .7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-dom-inspector-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-ins pector-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-js-debugger-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debu gger-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-mail-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1. 7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nspr-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-de vel-1.7.7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.7 .7-1.1.2.legacy.i386.rpm -
Red Hat Fedora mozilla-nss-devel-1.7.7-1.1.2.legacy.i386.rpm
Red Hat Fedora i386
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-dev el-1.7.7-1.1.2.legacy.i386.rpm
Mozilla Browser 1.4.2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.5
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.5.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 rc1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/ -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ gaim-1.2.0-i486-1.tgz -
Slackware gaim-1.2.0-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ gaim-1.2.0-i486-1.tgz -
Slackware mozilla-1.7.6-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-1.7.6-i486-1.tgz -
Slackware mozilla-1.7.6-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ mozilla-1.7.6-i486-1.tgz -
Slackware mozilla-plugins-1.7.6-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-plugins-1.7.6-noarch-1.tgz -
Slackware mozilla-plugins-1.7.6-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ mozilla-plugins-1.7.6-noarch-1.tgz
Mozilla Browser 1.7 rc2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 alpha
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 beta
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.3
-
Fedora mozilla-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-chat-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-chat-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-debuginfo-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-debuginfo-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-dom-inspector-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-dom-inspector-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-js-debugger-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-js-debugger-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-mail-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-mail-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nspr-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-devel-1.7.6-1.3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora mozilla-nss-devel-1.7.6-1.3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.4
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
S.u.S.E. Linux Professional 10.0
-
SuSE MozillaFirefox-1.0.8-0.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-1. 0.8-0.2.ppc.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbi rd-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunder bird-1.0.8-0.2.x86_64.rpm
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
S.u.S.E. Linux Professional 9.1
-
SuSE MozillaThunderbird-1.0.8-0.1.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaThunderbir d-1.0.8-0.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaThunde rbird-1.0.8-0.1.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Mozilla GIF Image Processing Library Remote Heap Overflow Vulnerability
References:
References:
- Cisco NX-OS Download Page (Cisco)
- Known Vulnerabilities in Mozilla (Mozilla)
- MFSA 2005-30 - GIF heap overflow parsing Netscape extension 2 (Mozilla)
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2005:323-10 Critical: mozilla security update (RedHat)
- RHSA-2005:335-07 Critical: mozilla security update (RedHat)
- RHSA-2005:336-03 Critical: firefox security update (RedHat)
- RHSA-2005:337-02 Critical: thunderbird security update (RedHat)
- Security Alerts (Netscape)
- SSA:2005-085-01 - Mozilla/Firefox/Thunderbird (Slackware)
- SSRT5940 rev.0 - HP-UX Mozilla remote, unauthorized user may execute privileged (HP)