| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.900894 |
| Kategorie: | Denial of Service |
| Titel: | Mozilla Firefox 'GIF' File DoS Vulnerability - Nov09 (Win) |
| Zusammenfassung: | Check for the version of Firefox |
| Beschreibung: | Overview: The host is installed with Firefox browser and is prone to Denial of Service vulnerabilities. Vulnerability Insight: A NULL pointer dereference error in 'nsGIFDecoder2::GifWrite' function in 'decoders/gif/nsGIFDecoder2.cpp' in libpr0n, which can be exploited to cause application crash via an animated 'GIF' file with a large image size. Impact: Successful exploitation could allows remote attacker to cause a vulnerable application to crash. Impact Level: Application Affected Software/OS: Mozilla Firefox version prior to 3.5.5 on Windows. Fix: Upgrade to Firefox version 3.5.5 or later, http://www.mozilla.com/en-US/firefox/all.html References: https://bugzilla.mozilla.org/show_bug.cgi?id=525326 https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3978 http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.html http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/ |
| Copyright | Copyright (C) 2009 SecPod |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|