CVE-2009-3978
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large…
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.htmlPatch
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_PlanPatch
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.htmlPatch
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_PlanPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.