CVE-2009-3978: Null Pointer Dereference
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3978?
CVE-2009-3978 has a severity rating of low, as it primarily causes a denial of service through application crashes.
How do I fix CVE-2009-3978?
To fix CVE-2009-3978, users should upgrade to Mozilla Firefox version 3.5.5 or later.
What versions of Firefox are affected by CVE-2009-3978?
CVE-2009-3978 affects Mozilla Firefox versions prior to 3.5.5, including all earlier versions.
What type of vulnerability is CVE-2009-3978?
CVE-2009-3978 is a denial of service vulnerability caused by a NULL pointer dereference.
Can CVE-2009-3978 be exploited remotely?
Yes, CVE-2009-3978 can be exploited remotely via specially crafted animated GIF files.