Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0800

Опубликовано: 02 апр. 2013
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5thunderbirdAffected
Red Hat Enterprise Linux 5thunderbirdFixedRHSA-2013:069702.04.2013
Red Hat Enterprise Linux 5firefoxFixedRHSA-2013:069602.04.2013
Red Hat Enterprise Linux 5xulrunnerFixedRHSA-2013:069602.04.2013
Red Hat Enterprise Linux 6firefoxFixedRHSA-2013:069602.04.2013
Red Hat Enterprise Linux 6xulrunnerFixedRHSA-2013:069602.04.2013
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2013:069702.04.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=946929Mozilla: Out-of-bounds write in Cairo library (MFSA 2013-31)

EPSS

Процентиль: 80%
0.01498
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.

nvd
больше 12 лет назад

Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.

debian
больше 12 лет назад

Integer signedness error in the pixman_fill_sse2 function in pixman-ss ...

github
больше 3 лет назад

Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.

oracle-oval
больше 12 лет назад

ELSA-2013-0697: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 80%
0.01498
Низкий

6.8 Medium

CVSS2