Уязвимость переполнения буфера в функции _cairo_truetype_index_to_ucs4 в Mozilla Firefox, Thunderbird и SeaMonkey при рендеринге шрифтов в PDF-документе
Описание
В функции _cairo_truetype_index_to_ucs4
библиотеки cairo, используемой в приложениях Mozilla Firefox, Thunderbird и SeaMonkey, обнаружена уязвимость переполнения буфера. Эта уязвимость позволяет злоумышленникам исполнять произвольный код через специально сформированное расширение, которое рендерит шрифты в PDF-документе.
Затронутые версии ПО
- Mozilla Firefox версии до 28.0
- Firefox ESR версии 24.x до 24.4
- Thunderbird версии до 24.4
- SeaMonkey версии до 2.25
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitIssue TrackingVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
EPSS
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo ...
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код
EPSS
8.8 High
CVSS3
6.8 Medium
CVSS2