Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://bugzilla.mozilla.org/show_bug.cgi?id=255067 http://www.vuxml.org/freebsd/ab9c559e-115a-11d9-bc4a-000c41e2cdad.html
Insight
The following packages are affected:
thunderbird
de-linux-mozillafirebird
el-linux-mozillafirebird
firefox
ja-linux-mozillafirebird-gtk1
ja-mozillafirebird-gtk2
linux-mozillafirebird
linux-phoenix
phoenix
ru-linux-mozillafirebird
zhCN-linux-mozillafirebird
zhTW-linux-mozillafirebird
de-netscape7
fr-netscape7
ja-netscape7
netscape7
pt_BR-netscape7
linux-mozilla
linux-mozilla-devel
mozilla-gtk1
mozilla
mozilla+ipv6
mozilla-embedded
mozilla-firebird
mozilla-gtk
mozilla-gtk2
mozilla-thunderbird
linux-netscape
de-linux-netscape
fr-linux-netscape
ja-linux-netscape
CVE-2004-0904
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
Severity
Classification
-
CVE CVE-2004-0904 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities