CVE-2009-2043: Input Validation
Published Jun 12, 2009
·Updated
nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.
Affected Software
9 affected components
Mozilla Firefox=3.0.7
Mozilla Firefox=3.0.9
Mozilla Firefox=3.0.8
Mozilla Firefox=3.0.4
Mozilla Firefox=3.0.5
Mozilla Firefox=3.0.10
Mozilla Firefox=3.0.3
Mozilla Firefox=3.0.6
Mozilla Firefox=3.0.2
Event History
Jun 12, 2009
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
Description
Frequently Asked Questions
1
Which Firefox versions are affected?
Mozilla Firefox 3.0.2 through 3.0.10 are identified as affected.
2
What does an attacker need to do to exploit this issue?
The issue can be triggered remotely through vectors related to interaction with TinyMCE. No authentication is required according to the provided attack vector.
3
What is the expected impact of successful exploitation?
Successful exploitation causes a NULL pointer dereference that crashes the Firefox application, resulting in denial of service. The provided impact rating indicates availability impact only, with no confidentiality or integrity impact.