Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
BID:37107
Info
Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
| Bugtraq ID: | 37107 |
| Class: | Design Error |
| CVE: |
CVE-2009-3978 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2009 12:00AM |
| Updated: | Nov 24 2009 04:35PM |
| Credit: | Mozilla |
| Vulnerable: |
Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 |
| Not Vulnerable: |
Mozilla Firefox 3.5.5 |
Discussion
Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
Mozilla Firefox is prone to a denial-of-service vulnerability when handling malformed GIF files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to Firefox 3.5.5 are affected.
Mozilla Firefox is prone to a denial-of-service vulnerability when handling malformed GIF files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to Firefox 3.5.5 are affected.
Exploit / POC
Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
GIF files that trigger this issue are available from the following location:
https://bugzilla.mozilla.org/show_bug.cgi?id=525326
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
GIF files that trigger this issue are available from the following location:
https://bugzilla.mozilla.org/show_bug.cgi?id=525326
Solution / Fix
Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Mozilla Firefox 'libpr0n' GIF File Handling Denial of Service Vulnerability
References:
References:
- Bug 525326 (Mozilla)
- Releases/Firefox 3.5.5/Test Plan (Mozilla)
- Vendor Homepage (Mozilla Foundation)