thunderbird: multiple vulnerabilities
| Package(s): | thunderbird |
CVE #(s): | |
| Created: | February 10, 2010 |
Updated: | February 11, 2010 |
| Description: |
From the Pardus advisory:
Security researcher Dan Kaminsky reported an integer overflow in the
Theora video library. A video's dimensions were being multiplied
together and used in particular memory allocations. When the video
dimensions were sufficiently large, the multiplication could overflow a
32-bit integer resulting in too small a memory buffer being allocated
for the video. An attacker could use a specially crafted video to write
data past the bounds of this buffer, causing a crash and potentially
running arbitrary code on a victim's computer.
|
| Alerts: |
| Pardus |
2010-30 |
thunderbird |
2010-02-09 |
|