CVE-2008-2934
published 2008-07-18CVE-2008-2934: Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a…
PriorityP431high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.59%
88.3th percentile
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-07-28·CVSS 9.3
CVE-2008-2785 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
A flaw was discovered in the browser engine. A variable could be made to
overflow causing the browser to crash. If a user were tricked into opening
a malicious web page, an attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2008-2785)
Billy Rios discovered that Firefox and xulrunner, as used by browsers
such as Epiphany, did not properly perform URI splitting with pipe
symbols when passed a command-line URI. If Firefox or xulrunner were
passed a malicious URL, an attacker may be able to execute local
content with chrome privileges. (CVE-2008-2933)
Instructions: After a standard system upgrade you need to restart
Red Hat
CVE-2008-2934: Mozilla Firefox 3 before 3
vendor_redhat·CVSS 8.8
CVE-2008-2934 [HIGH] CVE-2008-2934: Mozilla Firefox 3 before 3
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
Statement: Not vulnerable. This issue did not affect the versions of firefox as shipped with Red Hat Enterprise Linux 4, or 5.
GHSA
GHSA-vq9v-44rg-m34m: Mozilla Firefox 3 before 3
ghsa_unreviewed·2022-05-01
CVE-2008-2934 [MEDIUM] CWE-908 GHSA-vq9v-44rg-m34m: Mozilla Firefox 3 before 3
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Access of Uninitialized Pointer
mitre_cwe
CWE-824 Access of Uninitialized Pointer
CWE-824: Access of Uninitialized Pointer
The product accesses or uses a pointer that has not been initialized.
If the pointer contains an uninitialized value, then the value might not point to a valid memory location. This could cause the product to read from or write to unexpected memory locations, leading to a denial of service. If the uninitialized pointer is used as a function call, then arbitrary functions could be invoked. If an attacker can influence the portion of uninitialized memory that is contained in the pointer, this weakness could be leveraged to execute code or perform other attacks. Depending on memory layout, associated memory management behaviors, and product operation, the attacker might be able to influence the contents of the uninitialized pointer, thus gaining more
CWE
Improper Initialization
mitre_cwe
CWE-665 Improper Initialization
CWE-665: Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.
Modes of Introduction:
Phase: Implementation
Note: This weakness can occur in code paths that are not well-tested, such as rare error conditions. This is because the use of uninitialized data would be noticed as a bug during frequently-used functionality.
Phase: Operation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory, Read Application Data. When reusing a resource such as memory or a program
CWE
Use of Uninitialized Resource
mitre_cwe
CWE-908 Use of Uninitialized Resource
CWE-908: Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory, Read Application Data. When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. The uninitialized resource may contain values that cause program flow to change in ways that t
http://secunia.com/advisories/31132http://secunia.com/advisories/31270http://secunia.com/advisories/34501http://securitytracker.com/id?1020516http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mozilla.org/security/announce/2008/mfsa2008-36.htmlhttp://www.securityfocus.com/bid/30266http://www.ubuntu.com/usn/usn-626-1http://www.vupen.com/english/advisories/2008/2125http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=441360https://exchange.xforce.ibmcloud.com/vulnerabilities/43850http://secunia.com/advisories/31132http://secunia.com/advisories/31270http://secunia.com/advisories/34501http://securitytracker.com/id?1020516http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mozilla.org/security/announce/2008/mfsa2008-36.htmlhttp://www.securityfocus.com/bid/30266http://www.ubuntu.com/usn/usn-626-1http://www.vupen.com/english/advisories/2008/2125http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=441360https://exchange.xforce.ibmcloud.com/vulnerabilities/43850
2008-07-18
Published