CVE-2009-3987: Infoleak
Security researcher Gregory Fleischer reported that the exception messages generated by Mozilla's GeckoActiveXObject differ based on whether or not the requested COM object's ProgID is present in the system registry. A malicious site could use this vulnerability to enumerate a list of COM objects installed on a user's system and create a profile to track the user across browsing sessions.
Other sources
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3987?
CVE-2009-3987 is rated as moderate severity due to its potential for information disclosure.
How do I fix CVE-2009-3987?
To fix CVE-2009-3987, upgrade to a version of Mozilla Firefox that is not affected, specifically newer than 3.0.15.
What applications are affected by CVE-2009-3987?
CVE-2009-3987 affects multiple versions of Mozilla Firefox, including versions from 0.1 to 3.0.15.
Can CVE-2009-3987 allow attackers to exploit my system?
Yes, CVE-2009-3987 could allow attackers to enumerate COM objects, potentially leading to further attacks.
Is CVE-2009-3987 still a threat today?
CVE-2009-3987 is generally not a current threat if you are using recent versions of Firefox or other unaffected browsers.