VID |
28837 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Mozilla Firefox which is older than 3.6.17 has been installed on the host. Mozilla is an open-source based Web browser, developed by the Mozilla project. Mozilla Firefox versions 3.6.x prior to 3.6.17 are vulnerable to multiple vulnerabilities.
- Multiple use-after-free errors exist in the handling of the object attributes 'mChannel', 'mObserverList' and 'nsTreeRange'. (CVE-2011-0065, CVE-2011-0066, CVE-2011-0073) - An error exists in the handling of Java applets that can allow sensitive form history data to be accessed. (CVE-2011-0067) - An error in the resource protocol can allow a directory traversal attack. (CVE-2011-0071) - Multiple memory safety issues can lead to application crashes and possibly remote code execution. (CVE-2011-0069, CVE-2011-0070, CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, CVE-2011-0078, CVE-2011-0080) - An information disclosure vulnerability exists in the 'xsltGenerateIdFunction' function in the included libxslt library. (CVE-2011-1202)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.mozilla.org/security/announce/2011/mfsa2011-12.html http://www.mozilla.org/security/announce/2011/mfsa2011-13.html http://www.mozilla.org/security/announce/2011/mfsa2011-14.html http://www.mozilla.org/security/announce/2011/mfsa2011-16.html http://www.mozilla.org/security/announce/2011/mfsa2011-18.html http://www.mozilla.org/security/known-vulnerabilities/firefox36.html#firefox3.6.17
* Platforms Affected: Mozilla Project, Firefox versions 3.6.x prior to 3.6.17 Microsoft Windows Any version Linux Any version |
Recommendation |
Upgrade to the latest version of Firefox (3.6.17 or later), available from the Mozilla Firefox Download Web page at http://www.mozilla.org/ |
Related URL |
CVE-2011-0065,CVE-2011-0066,CVE-2011-0067,CVE-2011-0069,CVE-2011-0070,CVE-2011-0071,CVE-2011-0072,CVE-2011-0073,CVE-2011-0074 (CVE) |
Related URL |
47635 (SecurityFocus) |
Related URL |
(ISS) |
|