CVE-2009-3978

medium

Description

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.

References

http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc

https://bugzilla.mozilla.org/show_bug.cgi?id=525326

https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan

Details

Source: Mitre, NVD

Published: 2009-11-19

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Severity: Medium