Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902305
Kategorie:General
Titel:Mozilla Firefox Information Disclosure Vulnerability (Windows)
Zusammenfassung:The host is installed with Mozilla Firefox and is prone to Information; Disclosure Vulnerability.
Beschreibung:Summary:
The host is installed with Mozilla Firefox and is prone to Information
Disclosure Vulnerability.

Vulnerability Insight:
The flaws are due to:

- Error in 'Math.random' function in the JavaScript implementation which uses
a random number generator that is seeded only once per document object, which
makes it easier for remote attackers to track a user, or trick a user into
acting upon a spoofed pop-up message, by calculating the seed value.

- Error in 'js_InitRandom' function in the JavaScript implementation uses a
context pointer in conjunction with its successor pointer for seeding of a
random number generator, which makes it easier for remote attackers to guess
the seed value via a brute-force attack.

Vulnerability Impact:
Successful exploitation will let attackers to bypass the same-origin policy
and obtain potentially sensitive information. Other attacks are possible.

Affected Software/OS:
Firefox version 3.5.10 through 3.5.11

Firefox version 3.6.4 through 3.6.8 and 4.0 Beta1

Solution:
Upgrade to Mozilla Firefox version 3.6.9 or later, 3.5.12 or later, 4.0 Beta-2 or later.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-3171
BugTraq ID: 43222
http://www.securityfocus.com/bid/43222
Bugtraq: 20100914 New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1" (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2010-09/0117.html
http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdf
https://bugzilla.mozilla.org/show_bug.cgi?id=577512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7370
http://secunia.com/advisories/42867
http://www.vupen.com/english/advisories/2011/0061
Common Vulnerability Exposure (CVE) ID: CVE-2010-3399
https://bugzilla.mozilla.org/show_bug.cgi?id=475585
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7598
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.