{
  "threat_severity" : "Critical",
  "public_date" : "2009-10-27T00:00:00Z",
  "bugzilla" : {
    "description" : "Firefox heap buffer overflow in GIF color map parser",
    "id" : "530156",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=530156"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "cwe" : "CWE-122",
  "details" : [ "Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2009-10-27T00:00:00Z",
    "advisory" : "RHSA-2009:1530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "firefox-0:3.0.15-3.el4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2009-10-27T00:00:00Z",
    "advisory" : "RHSA-2009:1530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "nspr-0:4.7.6-1.el4_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2009-10-27T00:00:00Z",
    "advisory" : "RHSA-2009:1530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "firefox-0:3.0.15-3.el5_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2009-10-27T00:00:00Z",
    "advisory" : "RHSA-2009:1530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "nspr-0:4.7.6-1.el5_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2009-10-27T00:00:00Z",
    "advisory" : "RHSA-2009:1530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "xulrunner-0:1.9.0.15-3.el5_4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2009-3373\nhttps://nvd.nist.gov/vuln/detail/CVE-2009-3373" ],
  "name" : "CVE-2009-3373",
  "csaw" : false
}