CVE-2009-1828: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to do to trigger this issue?
An attacker needs to get a user to load content containing a KEYGEN element together with either a META-driven automatic page refresh or a BODY onLoad JavaScript handler. The issue is remotely triggerable and requires no authentication.
What is the practical impact on an affected browser?
The browser can enter an infinite loop, hang, and consume memory, resulting in a denial of service. The provided data does not indicate confidentiality or integrity impact.
Which Firefox versions should be considered at risk?
Firefox 3.0.10 is identified as affected, and reports indicate that earlier versions are also affected. The provided data does not identify a fixed version.