CVE-2009-3979: Critical severity mozilla seamonkey vulnerability
Mozilla developers and community members identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, and Olli Pettay reported crashes in the browser engine which affected both Firefox 3 and Firefox 3.5.
Other sources
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3979?
CVE-2009-3979 has been classified as a moderate severity vulnerability due to the potential for memory corruption leading to application crashes.
How do I fix CVE-2009-3979?
To mitigate CVE-2009-3979, update Mozilla Firefox to version 3.0.15 or later, as the vulnerability has been addressed in those releases.
What products are affected by CVE-2009-3979?
CVE-2009-3979 affects multiple versions of Mozilla Firefox prior to 3.0.15 as well as several early versions of the browser.
Can CVE-2009-3979 be exploited remotely?
Yes, CVE-2009-3979 can potentially be exploited remotely if a user visits a malicious web page designed to trigger the vulnerability.
What are the symptoms of CVE-2009-3979 exploitation?
Symptoms of exploitation of CVE-2009-3979 typically include unexpected crashes or freezing of the browser, indicating memory corruption.