Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2013-04-03T10:00:00
Updated: 2024-08-06T14:41:47.271Z
Reserved: 2013-01-02T00:00:00
Link: CVE-2013-0792
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-04-03T11:56:21.130
Modified: 2024-11-21T01:48:13.683
Link: CVE-2013-0792
Redhat