Description
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-046.html
Exploit, Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5665
Various Sources vendor-advisory
x_refsource_mandrake
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
Patch, Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-192.html
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=157989
Various Sources x_refsource_misc
http://crash.ihug.co.nz/~Sneuro/zerogif/
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103134051120770&w=2
Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10058.php
Scores
EPSS
0.0428
EPSS Percentile
90.0%
Details
Status
published
Products (13)
mozilla/mozilla
0.9.5
mozilla/mozilla
0.9.6
mozilla/mozilla
0.9.7
mozilla/mozilla
0.9.8
mozilla/mozilla
0.9.9
mozilla/mozilla
1.0
netscape/navigator
6.2
netscape/navigator
6.2.1
netscape/navigator
6.2.2
netscape/navigator
6.2.3
... and 3 more
Published
Oct 04, 2002
Tracked Since
Feb 18, 2026