← Back

CVE-2009-3378

nvd nist
Published: Oct 29, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.

Affected (3)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.5.1
Version 3.5.2
Version 3.5.3

Timeline

No history available yet.