First published: Fri Dec 11 2009(Updated: )
Mozilla developers and community members identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, and Olli Pettay reported crashes in the browser engine which affected both Firefox 3 and Firefox 3.5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | =1.1.10 | |
Firefox | =0.1 | |
Mozilla SeaMonkey | =1.0.3 | |
Firefox | =0.8 | |
Firefox | =2.0.0.12 | |
Firefox | =1.5-beta2 | |
Firefox | =2.0_.7 | |
Firefox | =3.5.3 | |
Mozilla SeaMonkey | =1.1.8 | |
Firefox | =3.0.7 | |
Firefox | =1.5.2 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.5.0.10 | |
Firefox | =3.0.9 | |
Mozilla SeaMonkey | =1.0.6 | |
Firefox | =1.5.0.6 | |
Firefox | =1.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1.3 | |
Firefox | =2.0.0.2 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.3 | |
Mozilla SeaMonkey | =2.0a1pre | |
Mozilla SeaMonkey | =1.0 | |
Firefox | =3.0.8 | |
Mozilla SeaMonkey | =1.1.17 | |
Firefox | =1.5.0.11 | |
Firefox | =1.4.1 | |
Mozilla SeaMonkey | =1.0.99 | |
Firefox | =1.5.4 | |
Mozilla SeaMonkey | =2.0-alpha_2 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.0.7 | |
Firefox | =1.0.2 | |
Mozilla SeaMonkey | =1.0-beta | |
Firefox | =3.5.5 | |
Firefox | =3.0.4 | |
Firefox | =1.5-beta1 | |
Mozilla SeaMonkey | =1.1-alpha | |
Firefox | =2.0_8 | |
Mozilla SeaMonkey | =2.0-alpha_3 | |
Firefox | =3.5.4 | |
Firefox | =2.0_.9 | |
Firefox | =3.0.5 | |
Mozilla SeaMonkey | =1.0-alpha | |
Firefox | <=3.0.15 | |
Mozilla SeaMonkey | =2.0a1 | |
Firefox | =1.5 | |
Firefox | =0.9.1 | |
Firefox | =1.0.4 | |
Firefox | =2.0.0.7 | |
Firefox | =1.0.7 | |
Mozilla SeaMonkey | =1.1.12 | |
Firefox | =3.5.1 | |
Mozilla SeaMonkey | =1.1 | |
Firefox | =2.0.0.9 | |
Firefox | =0.10.1 | |
Firefox | =2.0_.1 | |
Firefox | =3.0.14 | |
Firefox | =3.5.2 | |
Firefox | =0.9 | |
Firefox | =2.0.0.16 | |
Mozilla SeaMonkey | =1.1.14 | |
Firefox | =3.0-beta2 | |
Firefox | =1.5.6 | |
Firefox | =2.0.0.17 | |
Firefox | =0.7 | |
Mozilla SeaMonkey | =1.1.2 | |
Firefox | =2.0.0.15 | |
Mozilla SeaMonkey | =2.0-beta_2 | |
Firefox | =3.0.10 | |
Firefox | =0.2 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Firefox | =0.3 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =2.0-alpha_1 | |
Firefox | =2.0_.10 | |
Firefox | =3.0.12 | |
Firefox | =1.0 | |
Mozilla SeaMonkey | =1.5.0.9 | |
Firefox | =3.0.3 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Firefox | =1.5.0.7 | |
Firefox | =2.0 | |
Firefox | =1.0.1 | |
Mozilla SeaMonkey | =1.5.0.8 | |
Firefox | =2.0-beta1 | |
Firefox | =2.0.0.14 | |
Firefox | =0.6 | |
Mozilla SeaMonkey | =1.0.5 | |
Firefox | =0.7.1 | |
Mozilla SeaMonkey | =1.1.15 | |
Firefox | =3.0.6 | |
Firefox | =1.5.0.8 | |
Firefox | =2.0_.5 | |
Firefox | =2.0.0.3 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.7 | |
Firefox | =1.5.0.12 | |
Firefox | =2.0.0.6 | |
Mozilla SeaMonkey | =1.1.6 | |
Firefox | =3.0 | |
Firefox | =2.0.0.11 | |
Firefox | =1.5.0.2 | |
Mozilla SeaMonkey | =1.1.16 | |
Firefox | =1.0.3 | |
Firefox | =3.0.1 | |
Firefox | =2.0.0.4 | |
Firefox | =0.5 | |
Firefox | =0.6.1 | |
Firefox | =1.5.1 | |
Mozilla SeaMonkey | =2.0-beta_1 | |
Firefox | =2.0.0.21 | |
Firefox | =0.9.3 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0-rc2 | |
Firefox | =2.0.0.1 | |
Firefox | =3.0.2 | |
Firefox | =2.0_.6 | |
Firefox | =2.0_.4 | |
Mozilla SeaMonkey | =2.0-rc1 | |
Mozilla SeaMonkey | =1.0.4 | |
Firefox | =1.5.5 | |
Firefox | =0.9.2 | |
Firefox | =1.0-preview_release | |
Mozilla SeaMonkey | <=2.0 | |
Firefox | =2.0-beta_1 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Firefox | =2.0.0.20 | |
Firefox | =2.0.0.8 | |
Firefox | =3.0-beta5 | |
Firefox | =0.9-rc | |
Firefox | =2.0.0.19 | |
Firefox | =1.5.8 | |
Firefox | =1.5.3 | |
Firefox | =0.4 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.1 | |
Firefox | =3.0.13 | |
Firefox | =0.10 | |
Firefox | =1.0.5 | |
Firefox | =2.0.0.5 | |
Mozilla SeaMonkey | =2.0 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0-rc3 | |
Firefox | =3.0-alpha | |
Firefox | =1.0.6 | |
Mozilla SeaMonkey | =1.1.4 | |
Firefox | =1.0.8 | |
Firefox | =3.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3979 has been classified as a moderate severity vulnerability due to the potential for memory corruption leading to application crashes.
To mitigate CVE-2009-3979, update Mozilla Firefox to version 3.0.15 or later, as the vulnerability has been addressed in those releases.
CVE-2009-3979 affects multiple versions of Mozilla Firefox prior to 3.0.15 as well as several early versions of the browser.
Yes, CVE-2009-3979 can potentially be exploited remotely if a user visits a malicious web page designed to trigger the vulnerability.
Symptoms of exploitation of CVE-2009-3979 typically include unexpected crashes or freezing of the browser, indicating memory corruption.