Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 240592 (CVE-2008-4324) - www-client/mozilla-firefox<=3.0.3 user interface event dispatcher DOS (CVE-2008-4324)
Summary: www-client/mozilla-firefox<=3.0.3 user interface event dispatcher DOS (CVE-20...
Status: RESOLVED FIXED
Alias: CVE-2008-4324
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Low trivial (vote)
Assignee: Gentoo Security
URL: http://www.secniche.org/moz303/index....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-08 21:15 UTC by Stefan Behte (RETIRED)
Modified: 2008-11-30 17:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-10-08 21:15:47 UTC
CVE-2008-4324 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4324):
  The user interface event dispatcher in Mozilla Firefox 3.0.3 on
  Windows XP SP2 allows remote attackers to cause a denial of service
  (NULL pointer dereference and application crash) via a series of
  keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup
  events.  NOTE: it was later reported that Firefox 3.0.2 on Mac OS X
  10.5 is also affected.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-08 21:20:09 UTC
Confimed to work on 3.0.3!
I'm not sure if this also could be A2 (remote code exec): http://www.securityfocus.com/bid/31476/discuss
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-08 21:26:34 UTC
3.0.1-r1 crashes (just closes) after freezing for about 5 seconds.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-10-08 21:31:37 UTC
If it only affects the 3.x firefoxes, it should be ~ rated, and severity changed.
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-09 14:25:24 UTC
I tested 2.0.0.17 now, the exploit does not do anything to it, so I'm changing it.

They do not mention it here:
http://www.mozilla.org/security/known-vulnerabilities/firefox30.html

Upstream release plan for 3.0.4:
https://wiki.mozilla.org/Releases/Firefox_3.0.4

I'll ask.
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-09 15:12:35 UTC
https://bugzilla.mozilla.org/show_bug.cgi?id=454820
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-07 20:59:08 UTC
There is a fix available, please provide an ebuild.
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-30 17:03:58 UTC
3.0.4 in tree, closing noglsa.