Your system may not meet the requirements for Firefox, but you can try one of these versions:

Your system doesn't meet the requirements to run Firefox.

Your system doesn't meet the requirements to run Firefox.

Please follow these instructions to install Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2008-07

Possible information disclosure in BMP decoder

February 19, 2008
Gynvael Coldwind // Vexillium
Firefox, SeaMonkey
Fixed in
  • Firefox
  • SeaMonkey 1.1.8


Security researcher Gynvael Coldwind of Vexillium (crediting help from udevd and porneL) demonstrated that BMP images could be used to reveal small chunks of uninitialized memory that might contain sensitive data from other pages or other programs, and that this data could be extracted from the image using methods associated with the <canvas> feature.

Because this flaw also affected products from other vendors disclosure was delayed until they could release a fix.

Update: Thunderbird was incorrectly listed as affected by this vulnerability. The maliciously formed BMP images would contain noise influenced by uninitialized memory as in Firefox, but Thunderbird lacks the <canvas> feature necessary for an attacker to extract the data from the image.


Disable JavaScript until a version containing these fixes can be installed.