MEDIUM
Seamonkey: NULL pointer dereference in GIF decoder
Published Nov 19, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.79%
Description
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
Affected products
No data.
OR
- ≤ 3.5.4
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.6.1
- 0.7
- 0.7.1
- 0.8
- 0.9
- 0.9
- 0.9.1
- 0.9.2
- 0.9.3
- 0.10
- 0.10.1
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.4.1
- 1.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.8
- 2.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.10
- 2.0.0.11
- 3.0
- 3.0.5
- 3.5
- 3.5.2
- 3.5.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc x_refsource_CONFIRM
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.html x_refsource_MISCPatch
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/ x_refsource_MISCPatch
- https://access.redhat.com/security/cve/CVE-2009-3978 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=547292 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3978
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan x_refsource_CONFIRMPatch
- https://www.cve.org/CVERecord?id=CVE-2009-3978
| Link | Providers | Tags |
|---|---|---|
| http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc | x_refsource_CONFIRM | |
| http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.html | x_refsource_MISCPatch | |
| http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/ | x_refsource_MISCPatch | |
| https://access.redhat.com/security/cve/CVE-2009-3978 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=525326 | x_refsource_CONFIRM | |
| https://bugzilla.redhat.com/show_bug.cgi?id=547292 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3978 | ||
| https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan | x_refsource_CONFIRMPatch | |
| https://www.cve.org/CVERecord?id=CVE-2009-3978 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 19, 2009
Updated Sep 17, 2024
Reserved Nov 18, 2009
Link CVE-2009-3978
CISA Vulnrichment
Updated n/a