Vulnerability Description
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 3.5.4 |
References
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-Patch
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_PlanPatch
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-Patch
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_PlanPatch
FAQ
What is CVE-2009-3978?
CVE-2009-3978 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and app...
How severe is CVE-2009-3978?
CVE-2009-3978 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3978?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.