CVE-2012-4188

Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html Mailing List Third Party Advisory
http://osvdb.org/86096 Broken Link
http://rhn.redhat.com/errata/RHSA-2012-1351.html Third Party Advisory
http://secunia.com/advisories/50856 Third Party Advisory
http://secunia.com/advisories/50892 Third Party Advisory
http://secunia.com/advisories/50904 Third Party Advisory
http://secunia.com/advisories/50935 Third Party Advisory
http://secunia.com/advisories/50936 Third Party Advisory
http://secunia.com/advisories/50984 Third Party Advisory
http://secunia.com/advisories/51181 Third Party Advisory
http://secunia.com/advisories/55318 Third Party Advisory
http://www.debian.org/security/2012/dsa-2565 Third Party Advisory
http://www.debian.org/security/2012/dsa-2569 Third Party Advisory
http://www.debian.org/security/2012/dsa-2572 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:163 Third Party Advisory
http://www.mozilla.org/security/announce/2012/mfsa2012-86.html Vendor Advisory
http://www.ubuntu.com/usn/USN-1611-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=787722 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/79165 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16964 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html Mailing List Third Party Advisory
http://osvdb.org/86096 Broken Link
http://rhn.redhat.com/errata/RHSA-2012-1351.html Third Party Advisory
http://secunia.com/advisories/50856 Third Party Advisory
http://secunia.com/advisories/50892 Third Party Advisory
http://secunia.com/advisories/50904 Third Party Advisory
http://secunia.com/advisories/50935 Third Party Advisory
http://secunia.com/advisories/50936 Third Party Advisory
http://secunia.com/advisories/50984 Third Party Advisory
http://secunia.com/advisories/51181 Third Party Advisory
http://secunia.com/advisories/55318 Third Party Advisory
http://www.debian.org/security/2012/dsa-2565 Third Party Advisory
http://www.debian.org/security/2012/dsa-2569 Third Party Advisory
http://www.debian.org/security/2012/dsa-2572 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2012:163 Third Party Advisory
http://www.mozilla.org/security/announce/2012/mfsa2012-86.html Vendor Advisory
http://www.ubuntu.com/usn/USN-1611-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=787722 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/79165 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16964 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_sdk:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

History

No history.

Information

Published : 2012-10-10 17:55

Updated : 2025-04-11 00:51


NVD link : CVE-2012-4188

Mitre link : CVE-2012-4188

CVE.ORG link : CVE-2012-4188


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_server

mozilla

  • thunderbird_esr
  • thunderbird
  • firefox
  • seamonkey

debian

  • debian_linux

suse

  • linux_enterprise_desktop
  • linux_enterprise_server
  • linux_enterprise_sdk

canonical

  • ubuntu_linux
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer