You are here: Known Vulnerabilities in Mozilla Products (Firefox > MFSA 2006-69

Mozilla Foundation Security Advisory 2006-69

Title: CSS cursor image buffer overflow (Windows only)
Impact: Critical
Announced: December 19, 2006
Reporter: Frederik Reiss
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox
  SeaMonkey 1.0.7


Frederik Reiss reported a crash when using the CSS cursor property to set the cursor to certain images on Windows. A miscalculated size during conversion of the image to a Windows bitmap can result in a heap buffer overflow which could be used to compromise the victim's computer.

This flaw affects both Firefox 2 and Firefox 1.5 but not the earlier Firefox 1.0 or Mozilla Suite


Upgrade to a fixed version.