CVE-2008-2934

Current Description

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

Basic Data

PublishedJuly 18, 2008
Last ModifiedAugust 08, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-94
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score6.8
SeverityMEDIUM
Exploitability Score8.6
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • AND
    • OR - Configuration 1
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3OSAppleMac Os X********
    • OR Running on/with:
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3ApplicationMozillaFirefox3.0*******

Vulnerable Software List

VendorProductVersions
Mozilla Firefox 3.0

References

NameSourceURLTags
31132http://secunia.com/advisories/31132SECUNIAVendor Advisory
31270http://secunia.com/advisories/31270SECUNIA
34501http://secunia.com/advisories/34501SECUNIA
1020516http://securitytracker.com/id?1020516SECTRACK
256408http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1SUNALERT
http://www.mozilla.org/security/announce/2008/mfsa2008-36.htmlhttp://www.mozilla.org/security/announce/2008/mfsa2008-36.htmlCONFIRM
30266http://www.securityfocus.com/bid/30266BID
USN-626-1http://www.ubuntu.com/usn/usn-626-1UBUNTU
ADV-2008-2125http://www.vupen.com/english/advisories/2008/2125VUPEN
ADV-2009-0977http://www.vupen.com/english/advisories/2009/0977VUPEN
https://bugzilla.mozilla.org/show_bug.cgi?id=441360https://bugzilla.mozilla.org/show_bug.cgi?id=441360CONFIRM
firefox-gif-code-execution(43850)https://exchange.xforce.ibmcloud.com/vulnerabilities/43850XF