CVE-2009-3382: Critical severity firefox vulnerability
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3382?
CVE-2009-3382 is classified as a security vulnerability that can lead to denial of service and possibly arbitrary code execution.
How do I fix CVE-2009-3382?
To fix CVE-2009-3382, upgrade your Mozilla Firefox to version 3.0.15 or later.
Which versions of Firefox are affected by CVE-2009-3382?
CVE-2009-3382 affects Mozilla Firefox versions 3.0.1 through 3.0.14.
What type of vulnerability is CVE-2009-3382?
CVE-2009-3382 is a memory corruption vulnerability that affects the rendering of first-letter frames in Firefox.
Can CVE-2009-3382 be exploited remotely?
Yes, CVE-2009-3382 can be exploited remotely, potentially allowing attackers to crash the browser or execute arbitrary code.