CVE-2012-4186

Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.

Published at
2012-10-10T17:55Z
4224 days ago
Modified
2020-08-11T13:43Z
1362 days ago
CWE-119
Problem type

References


URLType
www.mozilla.org
http://www.mozilla.org/security/announce/2012/mfsa2012-86.html
CONFIRM
bugzilla.mozilla.org
https://bugzilla.mozilla.org/show_bug.cgi?id=785967
CONFIRM
RHSA-2012:1351
http://rhn.redhat.com/errata/RHSA-2012-1351.html
REDHAT
DSA-2569
http://www.debian.org/security/2012/dsa-2569
DEBIAN
DSA-2565
http://www.debian.org/security/2012/dsa-2565
DEBIAN
USN-1611-1
http://www.ubuntu.com/usn/USN-1611-1
UBUNTU
SUSE-SU-2012:1351
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html
SUSE
DSA-2572
http://www.debian.org/security/2012/dsa-2572
DEBIAN
86117
http://osvdb.org/86117
OSVDB
MDVSA-2012:163
http://www.mandriva.com/security/advisories?name=MDVSA-2012:163
MANDRIVA
50936
http://secunia.com/advisories/50936
SECUNIA
50935
http://secunia.com/advisories/50935
SECUNIA
50856
http://secunia.com/advisories/50856
SECUNIA
50984
http://secunia.com/advisories/50984
SECUNIA
50904
http://secunia.com/advisories/50904
SECUNIA
50892
http://secunia.com/advisories/50892
SECUNIA
51181
http://secunia.com/advisories/51181
SECUNIA
55318
http://secunia.com/advisories/55318
SECUNIA
firefox-nswavereader-bo(79163)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79163
XF
oval:org.mitre.oval:def:16193
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16193
OVAL

GET https://vulnerabilitydata.com/api/details/CVE-2012-4186

{
	"id": "CVE-2012-4186",
	"published_date": "2012-10-10T17:55Z",
	"last_modified_date": "2020-08-11T13:43Z",
	"assigner": "cve@mitre.org",
	"description": "Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.",
	"references": [
		{
			"url": "http://www.mozilla.org/security/announce/2012/mfsa2012-86.html",
			"name": "http://www.mozilla.org/security/announce/2012/mfsa2012-86.html",
			"refsource": "CONFIRM",
			"tags": [
				"Vendor Advisory"
			]
		},
		{
			"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=785967",
			"name": "https://bugzilla.mozilla.org/show_bug.cgi?id=785967",
			"refsource": "CONFIRM",
			"tags": [
				"Issue Tracking"
			]
		},
		{
			"url": "http://rhn.redhat.com/errata/RHSA-2012-1351.html",
			"name": "RHSA-2012:1351",
			"refsource": "REDHAT",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.debian.org/security/2012/dsa-2569",
			"name": "DSA-2569",
			"refsource": "DEBIAN",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.debian.org/security/2012/dsa-2565",
			"name": "DSA-2565",
			"refsource": "DEBIAN",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.ubuntu.com/usn/USN-1611-1",
			"name": "USN-1611-1",
			"refsource": "UBUNTU",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html",
			"name": "SUSE-SU-2012:1351",
			"refsource": "SUSE",
			"tags": [
				"Mailing List",
				"Third Party Advisory"
			]
		},
		{
			"url": "http://www.debian.org/security/2012/dsa-2572",
			"name": "DSA-2572",
			"refsource": "DEBIAN",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://osvdb.org/86117",
			"name": "86117",
			"refsource": "OSVDB",
			"tags": [
				"Broken Link"
			]
		},
		{
			"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:163",
			"name": "MDVSA-2012:163",
			"refsource": "MANDRIVA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50936",
			"name": "50936",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50935",
			"name": "50935",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50856",
			"name": "50856",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50984",
			"name": "50984",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50904",
			"name": "50904",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/50892",
			"name": "50892",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/51181",
			"name": "51181",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "http://secunia.com/advisories/55318",
			"name": "55318",
			"refsource": "SECUNIA",
			"tags": [
				"Third Party Advisory"
			]
		},
		{
			"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79163",
			"name": "firefox-nswavereader-bo(79163)",
			"refsource": "XF",
			"tags": [
				"Third Party Advisory",
				"VDB Entry"
			]
		},
		{
			"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16193",
			"name": "oval:org.mitre.oval:def:16193",
			"refsource": "OVAL",
			"tags": [
				"Third Party Advisory"
			]
		}
	],
	"impact": {
		"baseMetricV2": {
			"cvssV2": {
				"version": "2.0",
				"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
				"accessVector": "NETWORK",
				"accessComplexity": "MEDIUM",
				"authentication": "NONE",
				"confidentialityImpact": "COMPLETE",
				"integrityImpact": "COMPLETE",
				"availabilityImpact": "COMPLETE",
				"baseScore": 9.3
			},
			"severity": "HIGH",
			"exploitabilityScore": 8.6,
			"impactScore": 10,
			"acInsufInfo": false,
			"obtainAllPrivilege": false,
			"obtainUserPrivilege": false,
			"obtainOtherPrivilege": false,
			"userInteractionRequired": true
		}
	},
	"problem_type": "CWE-119"
}