Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-1960
HistoryJul 17, 2012 - 12:00 a.m.

CVE-2012-1960

2012-07-1700:00:00
ubuntu.com
ubuntu.com
13

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

77.6%

The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS
implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through
13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain
sensitive information from process memory via a crafted color profile that
triggers an out-of-bounds read operation.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchfirefox< 14.0.1+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchfirefox< 14.0.1+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchfirefox< 14.0.1+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchfirefox< 14.0.1+build1-0ubuntu0.12.04.1UNKNOWN
ubuntu10.04noarchthunderbird< 14.0+build1-0ubuntu0.10.04.1UNKNOWN
ubuntu11.04noarchthunderbird< 14.0+build1-0ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarchthunderbird< 14.0+build1-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchthunderbird< 14.0+build1-0ubuntu0.12.04.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

77.6%