Lucene search

K
mozillaMozilla FoundationMFSA2013-116
HistoryDec 10, 2013 - 12:00 a.m.

JPEG information leak — Mozilla

2013-12-1000:00:00
Mozilla Foundation
www.mozilla.org
39

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.006 Low

EPSS

Percentile

78.4%

Google security researcher Michal Zalewski reported issues with JPEG format image processing with Start Of Scan (SOS) and Define Huffman Table (DHT) markers in the libjpeg library. This could allow for the possible reading of arbitrary memory content as well as cross-domain image theft.

Affected configurations

Vulners
Node
mozillafirefoxRange<26
OR
mozillafirefox_esrRange<24.2
OR
mozillaseamonkeyRange<2.23
OR
mozillathunderbirdRange<24.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

0.006 Low

EPSS

Percentile

78.4%