VID |
28788 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Mozilla Firefox which is older than 3.0.12 has been installed on the host. Mozilla is an open-source based Web browser, developed by the Mozilla project. Mozilla Firefox versions 3.0.x prior to 3.0.12 are vulnerable to multiple vulnerabilities.
- Multiple memory corruption vulnerabilities could potentially be exploited to execute arbitrary code. (MFSA 2009-34)
- It may be possible to crash the browser or potentially execute arbitrary code by using a flash object that presents a slow script dialog. (MFSA 2009-35)
- Glyph rendering libraries are affected by multiple heap/integer overflows. (MFSA 2009-36)
- A vulnerability involving SVG element could be exploited to crash the browser or execute arbitrary code on the remote system. (MFSA 2009-37)
- A SOCKS5 proxy that replies with a hostname containing more than 15 characters can corrupt the subsequent data stream. This can lead to a denial of service, though there is reportedly no memory corruption.(MFSA 2009-38)
- A vulnerability in 'setTimeout' could allow unsafe access to the 'this' object from chrome code. An attacker could exploit this flaw to run arbitrary JavaScript with chrome privileges. (MFSA 2009-39)
- It may be possible for JavaScript from one website to bypass cross origin wrapper, and unsafely access properties of an object from another website.(MFSA 2009-40)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.mozilla.org/security/announce/2009/mfsa2009-34.html http://www.mozilla.org/security/announce/2009/mfsa2009-35.html http://www.mozilla.org/security/announce/2009/mfsa2009-36.html http://www.mozilla.org/security/announce/2009/mfsa2009-37.html http://www.mozilla.org/security/announce/2009/mfsa2009-38.html http://www.mozilla.org/security/announce/2009/mfsa2009-39.html http://www.mozilla.org/security/announce/2009/mfsa2009-40.html
* Platforms Affected: Mozilla Project, Firefox versions 3.0.x prior to 3.0.12 Microsoft Windows Any version Linux Any version |
Recommendation |
Upgrade to the latest version of Firefox (3.0.12 or later), available from the Mozilla Firefox Download Web page at http://www.mozilla.or.kr/ |
Related URL |
CVE-2009-1194,CVE-2009-2462,CVE-2009-2463,CVE-2009-2464,CVE-2009-2465,CVE-2009-2466,CVE-2009-2467,CVE-2009-2468,CVE-2009-2469,CVE-2009-2470 (CVE) |
Related URL |
35765,35766,35767,35769,35770,35772,35773,35774,35775,35776,35925 (SecurityFocus) |
Related URL |
(ISS) |
|