Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00022.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-11/msg00090.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-11/msg00092.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2012-11/msg00093.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1482.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1483.html Third Party Advisory
http://secunia.com/advisories/51359 Third Party Advisory
http://secunia.com/advisories/51360 Third Party Advisory
http://secunia.com/advisories/51369 Third Party Advisory
http://secunia.com/advisories/51370 Third Party Advisory
http://secunia.com/advisories/51381 Third Party Advisory
http://secunia.com/advisories/51434 Third Party Advisory
http://secunia.com/advisories/51439 Third Party Advisory
http://secunia.com/advisories/51440 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:173 Third Party Advisory
http://www.mozilla.org/security/announce/2012/mfsa2012-92.html Vendor Advisory
http://www.securityfocus.com/bid/56614 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1636-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1638-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1638-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-1638-3 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=758200 Issue Tracking Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/80170 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16739 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-11-21T11:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2012-08-08T00:00:00


Link: CVE-2012-4202

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-11-21T12:55:01.570

Modified: 2020-08-06T16:49:58.670


Link: CVE-2012-4202

JSON object: View

cve-icon Redhat Information

No data.

CWE