9.3
CVSSv2

CVE-2009-3389

Published: 17/12/2009 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in libtheora in Xiph.Org Theora prior to 1.1, as used in Mozilla Firefox 3.5 prior to 3.5.6 and SeaMonkey prior to 2.0.1, allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5.5

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.6

mozilla seamonkey 2.0

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1.5

mozilla seamonkey 2.0a1

mozilla seamonkey 2.0a1pre

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla seamonkey 1.0.5

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.8

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla seamonkey

mozilla firefox 3.5.3

mozilla firefox 3.5.4

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.99

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.7

Vendor Advisories

Debian Bug report logs - #572950 libtheora: multiple vulnerabilities in lenny Package: libtheora; Maintainer for libtheora is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sun, 7 Mar 2010 19:51:01 UTC Severity: serious Tags: lenny ...
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and David James discovered several flaws in the browser and JavaScript engines of Firefox If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the pr ...
USN-874-1 fixed vulnerabilities in Firefox and Xulrunner The upstream changes introduced a regression when using NTLM authentication This update fixes the problem and adds additional stability fixes ...
Bob Clary, Dan Kaminsky and David Keeler discovered that in libtheora, a video library part of the Ogg project, several flaws allow context-dependent attackers via a large and specially crafted media file, to cause a denial of service (crash of the player using this library), and possibly arbitrary code execution For the stable distribution (lenny ...
Mozilla Foundation Security Advisory 2009-67 Integer overflow, crash in libtheora video library Announced December 15, 2009 Reporter Dan Kaminsky, David Keeler Impact Critical Products Firefox, SeaMonkey, Thunderbird Fi ...