CVE-2009-3384
published 2009-11-13CVE-2009-3384: Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.48%
87.9th percentile
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.3 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Firefox integer underflow in FTP directory list parser
vendor_redhat·2009-10-27·CVSS 9.3
CVE-2009-3384 [CRITICAL] CWE-190 Firefox integer underflow in FTP directory list parser
Firefox integer underflow in FTP directory list parser
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
GHSA
GHSA-j32g-6wjv-jxxr: Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4
ghsa_unreviewed·2022-05-02
CVE-2009-3384 [HIGH] GHSA-j32g-6wjv-jxxr: Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3384 Firefox integer underflow in FTP directory list parser
bugzilla·2009-10-21·CVSS 9.3
CVE-2009-3384 [CRITICAL] CVE-2009-3384 Firefox integer underflow in FTP directory list parser
CVE-2009-3384 Firefox integer underflow in FTP directory list parser
Security researcher Michal Zalewski reported that the parser for FTP
directory listings was improperly checking for the end of a string buffer,
resulting in an integer underflow of a counter variable. This counter would
later be used as an array index and could result in the execution of an
arbitrary memory location. An attacker could potentially use this
vulnerability to crash a victim's browser and run arbitrary code on their
computer.
Discussion:
The Mozilla bug is here:
https://bugzilla.mozilla.org/show_bug.cgi?id=515583
---
Here is the relevant mozilla patch:
http://hg.mozilla.org/mozilla-central/rev/cade5b705114
This was fixed in:
Seamonkey:
Patch: mozilla-515583-x.patch
* Mon Oct 12 2009 Martin Stransky - 1
Bugzilla
CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directory listings
bugzilla·2009-09-25·CVSS 9.3
CVE-2009-3384 [CRITICAL] CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directory listings
CVE-2009-3384 WebKit, qt: Multiple security issues while handling FTP directory listings
Multiple security flaws (integer underflow, invalid pointer dereference,
buffer underflow and a denial of service) were found in the way WebKit's
FTP parser used to process remote FTP directory listings. If a remote
FTP server issued a specially-crafted FTP command, it could lead to
disclosure of sensitive information, denial of service (application crash) or,
potentially to execution of arbitrary code, once the command was parsed.
Upstream bug report:
https://bugs.webkit.org/show_bug.cgi?id=29294
Upstream patch:
http://trac.webkit.org/changeset/48725
Credit:
Michal Zalewski
Discussion:
This issue affects latest versions of WebKit package, as shipped with
Fedora release of 10 and 11 (WebKit-1.1.0
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/59943http://secunia.com/advisories/37346http://secunia.com/advisories/37393http://secunia.com/advisories/37397http://secunia.com/advisories/43068http://support.apple.com/kb/HT3949http://support.apple.com/kb/HT4013http://www.securityfocus.com/bid/36995http://www.securitytracker.com/id?1023166http://www.vupen.com/english/advisories/2009/3217http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=525788https://exchange.xforce.ibmcloud.com/vulnerabilities/54241https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6362https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/59943http://secunia.com/advisories/37346http://secunia.com/advisories/37393http://secunia.com/advisories/37397http://secunia.com/advisories/43068http://support.apple.com/kb/HT3949http://support.apple.com/kb/HT4013http://www.securityfocus.com/bid/36995http://www.securitytracker.com/id?1023166http://www.vupen.com/english/advisories/2009/3217http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=525788https://exchange.xforce.ibmcloud.com/vulnerabilities/54241https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6362https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.html
2009-11-13
Published