Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2014.0421
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2014-0421)
Zusammenfassung:The remote host is missing an update for the 'firefox, firefox-l10n, libpng, libvpx, nss, sqlite3, thunderbird, thunderbird-l10n, thunderbird-lightning' package(s) announced via the MGASA-2014-0421 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, libpng, libvpx, nss, sqlite3, thunderbird, thunderbird-l10n, thunderbird-lightning' package(s) announced via the MGASA-2014-0421 advisory.

Vulnerability Insight:
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox or Thunderbird to crash
or, potentially, execute arbitrary code with the privileges of the user
running it (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576,
CVE-2014-1577).

A flaw was found in the Alarm API in Firefox, which allows applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass cross-origin restrictions (CVE-2014-1583).

This update provides Firefox and Thunderbird 31.2, which fixes these issues
and other bugs, and also provides several new features, including WebRTC
support. The thunderbird-lightning package has also been updated to version
3.3 which is compatible with the new Thunderbird version.

Also, Enigmail (part of the Thunderbird package) has been updated to version
1.7.2 which contains several bugfixes including mail with only Bcc recipients
being sent in plain text unexpectedly (CVE-2014-5369).

Affected Software/OS:
'firefox, firefox-l10n, libpng, libvpx, nss, sqlite3, thunderbird, thunderbird-l10n, thunderbird-lightning' package(s) on Mageia 3, Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-1574
BugTraq ID: 70436
http://www.securityfocus.com/bid/70436
Debian Security Information: DSA-3050 (Google Search)
http://www.debian.org/security/2014/dsa-3050
Debian Security Information: DSA-3061 (Google Search)
http://www.debian.org/security/2014/dsa-3061
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html
https://security.gentoo.org/glsa/201504-01
RedHat Security Advisories: RHSA-2014:1635
http://rhn.redhat.com/errata/RHSA-2014-1635.html
RedHat Security Advisories: RHSA-2014:1647
http://rhn.redhat.com/errata/RHSA-2014-1647.html
http://www.securitytracker.com/id/1031028
http://www.securitytracker.com/id/1031030
http://secunia.com/advisories/61387
http://secunia.com/advisories/61854
http://secunia.com/advisories/62021
http://secunia.com/advisories/62022
http://secunia.com/advisories/62023
SuSE Security Announcement: openSUSE-SU-2014:1343 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-11/msg00000.html
SuSE Security Announcement: openSUSE-SU-2014:1344 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html
SuSE Security Announcement: openSUSE-SU-2014:1345 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html
SuSE Security Announcement: openSUSE-SU-2014:1346 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-11/msg00003.html
SuSE Security Announcement: openSUSE-SU-2015:0138 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.ubuntu.com/usn/USN-2372-1
http://www.ubuntu.com/usn/USN-2373-1
Common Vulnerability Exposure (CVE) ID: CVE-2014-1576
BugTraq ID: 70430
http://www.securityfocus.com/bid/70430
Common Vulnerability Exposure (CVE) ID: CVE-2014-1577
BugTraq ID: 70440
http://www.securityfocus.com/bid/70440
Common Vulnerability Exposure (CVE) ID: CVE-2014-1578
BugTraq ID: 70428
http://www.securityfocus.com/bid/70428
Common Vulnerability Exposure (CVE) ID: CVE-2014-1581
BugTraq ID: 70426
http://www.securityfocus.com/bid/70426
Common Vulnerability Exposure (CVE) ID: CVE-2014-1583
BugTraq ID: 70424
http://www.securityfocus.com/bid/70424
Common Vulnerability Exposure (CVE) ID: CVE-2014-5369
http://www.openwall.com/lists/oss-security/2014/08/18/2
http://www.openwall.com/lists/oss-security/2014/08/22/1
http://secunia.com/advisories/60779
http://secunia.com/advisories/60887
SuSE Security Announcement: openSUSE-SU-2014:1086 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00004.html
SuSE Security Announcement: openSUSE-SU-2014:1096 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00008.html
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.