VID |
28781 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Mozilla Firefox which is older than 3.5.3 has been installed on the host. Mozilla is an open-source based Web browser, developed by the Mozilla project. Mozilla Firefox versions 3.5.x prior to 3.5.3 are vulnerable to multiple vulnerabilities.
- Multiple memory corruption vulnerabilities could potentially allow arbitrary code execution. (MFSA 2009-47)
- The columns of a XUL tree element can manipulated in a way that leads to a dangling pointer. A remote attacker could exploit this to crash the browser, or execute arbitrary code. (MFSA 2009-49)
- A URL containing certain Unicode characters with tall tall-line height is displayed incorrectly in the location bar. A remote attacker could use this to prevent a user from seeing the full URL of a malicious web site. (MFSA 2009-50)
- A remote attacker can leverage 'BrowserFeedWriter' to execute JavaScript code with Chrome privileges. (MFSA 2009-51)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.mozilla.org/security/announce/2009/mfsa2009-47.html http://www.mozilla.org/security/announce/2009/mfsa2009-49.html http://www.mozilla.org/security/announce/2009/mfsa2009-50.html http://www.mozilla.org/security/announce/2009/mfsa2009-51.html
* Platforms Affected: Mozilla Project, Firefox versions 3.5.x prior to 3.5.3 Microsoft Windows Any version Linux Any version |
Recommendation |
Upgrade to the latest version of Firefox (3.5.3 or later), available from the Mozilla Firefox Download Web page at http://www.mozilla.or.kr/ko/ |
Related URL |
CVE-2009-3072,CVE-2009-3073,CVE-2009-3077,CVE-2009-3078,CVE-2009-3079 (CVE) |
Related URL |
36343 (SecurityFocus) |
Related URL |
(ISS) |
|