The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox...
Vulnerability Description
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-3978
Credits & Attribution
No credits recorded in the NVD database.
References
- http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc
- http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/
- http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.html
- https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan
- https://bugzilla.mozilla.org/show_bug.cgi?id=525326
More from mozilla
View All →Affected Vendor
mozilla
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.