CVE-2009-0071: Null Pointer Dereference
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not enable document.designMode (do not set designMode to 'on' or use editor pages that enable it). Disable or avoid use of designMode in affected Firefox installations to prevent the NULL pointer dereference crash (vulnerable in Firefox 3.0.5 and earlier 3.0.x; 3.0.6 and 3.0.7 were later reported affected).
Firefox designMode = disabled - Operational
Inventory Firefox installations and identify versions 3.0.7 and earlier (all 3.0.x up through 3.0.7). Isolate or remove those affected installations from general use until a vendor-provided fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0071?
CVE-2009-0071 is classified as a moderate severity vulnerability that can lead to application crashes.
How do I fix CVE-2009-0071?
To fix CVE-2009-0071, upgrade to a later version of Mozilla Firefox that has addressed this vulnerability.
What versions of Mozilla Firefox are affected by CVE-2009-0071?
CVE-2009-0071 affects Mozilla Firefox versions 3.0.5 and earlier including 3.0.x versions.
What kind of attack does CVE-2009-0071 involve?
CVE-2009-0071 allows remote attackers to cause a denial of service via specific DOM manipulations.
Is CVE-2009-0071 a denial of service vulnerability?
Yes, CVE-2009-0071 is a denial of service vulnerability due to a NULL pointer dereference.