CVE-2009-1827: Medium severity Mozilla Firefox vulnerability
Published May 29, 2009
·Updated
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."
Affected Software
1 affected component
Mozilla Firefox=3.0.4
Event History
May 29, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What user interaction is required for exploitation?
An attacker can trigger the application hang remotely by causing Firefox to process an SVG circle element with a large Radius (r) attribute. The supplied vector indicates network access, low attack complexity, and no authentication requirement.
2
What is the impact of a successful exploit?
The documented impact is a denial of service: Firefox can hang while processing the malformed SVG content. No confidentiality or integrity impact is indicated in the supplied severity vector.