Lucene search

K
mozillaMozilla FoundationMFSA2014-78
HistoryOct 14, 2014 - 12:00 a.m.

Further uninitialized memory use during GIF rendering — Mozilla

2014-10-1400:00:00
Mozilla Foundation
www.mozilla.org
33

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.4%

Google security researcher Michal Zalewski reported that when a malformed GIF image is repeatedly rendered within a element, memory may not always be properly initialized. The resulting series of images then uses this uninitialized memory during rendering, allowing data to potentially leak to web content.

Affected configurations

Vulners
Node
mozillafirefoxRange<33
OR
mozillafirefox_osRange<2.2
OR
mozillaseamonkeyRange<2.30

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.4%