{"id":"CVE-2009-3378","details":"The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.","modified":"2026-01-27T04:09:57.796870Z","published":"2009-10-29T14:30:01Z","withdrawn":"2026-01-27T04:09:57.796870Z","related":["openSUSE-SU-2024:10071-1"],"references":[{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2009:294"},{"type":"FIX","url":"http://www.mozilla.org/security/announce/2009/mfsa2009-63.html"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2009/3334"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=500311"},{"type":"WEB","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6443"}],"schema_version":"1.7.3"}