CVE-2009-1392: Code Injection
Mozilla developers and community members identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
Bob Clary, Jesse Ruderman, Alexander Sack, Bret McMillan, Tomeo Vizoso, Matt McCutchen, and Martijn Wargers reported crashes in the Firefox 3 browser engine.
Other sources
The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PLDHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1392?
The severity of CVE-2009-1392 is high, as it involves potential memory corruption leading to crashes.
How do I fix CVE-2009-1392?
To fix CVE-2009-1392, upgrade your Mozilla Firefox, SeaMonkey, or Thunderbird to the latest version that addresses this vulnerability.
What versions are affected by CVE-2009-1392?
CVE-2009-1392 affects specific versions of Mozilla Firefox, SeaMonkey, and Thunderbird, including Firefox 3.0.7 and SeaMonkey 1.1.10.
What products are impacted by CVE-2009-1392?
CVE-2009-1392 impacts Mozilla Firefox, Mozilla SeaMonkey, and Mozilla Thunderbird.
Is CVE-2009-1392 a remote code execution vulnerability?
CVE-2009-1392 does not explicitly indicate remote code execution but involves memory corruption which could potentially lead to such risks.