Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2015.0025
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2015-0025)
Zusammenfassung:The remote host is missing an update for the 'firefox, firefox-l10n, thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2015-0025 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, thunderbird, thunderbird-l10n' package(s) announced via the MGASA-2015-0025 advisory.

Vulnerability Insight:
Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox or Thunderbird to
crash or, potentially, execute arbitrary code with the privileges of the
user running it (CVE-2014-8634).

It was found that the Beacon interface implementation in Firefox and
Thunderbird did not follow the Cross-Origin Resource Sharing (CORS)
specification. A web page containing malicious content could allow a remote
attacker to conduct a Cross-Site Request Forgery (XSRF) attack
(CVE-2014-8638).

It was found that a Web Proxy returning a 407 Proxy Authentication response
with a Set-Cookie header could inject cookies into the originally requested
domain. This could be used for session-fixation attacks. This attack only
allows cookies to be written but does not allow them to be read
(CVE-2014-8639).

Security researcher Mitchell Harper discovered a read-after-free in WebRTC
due to the way tracks are handled. This results in a either a potentially
exploitable crash or incorrect WebRTC behavior. Note that this issue only
affects Firefox (CVE-2014-8641).

Affected Software/OS:
'firefox, firefox-l10n, thunderbird, thunderbird-l10n' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-8634
BugTraq ID: 72049
http://www.securityfocus.com/bid/72049
Debian Security Information: DSA-3127 (Google Search)
http://www.debian.org/security/2015/dsa-3127
Debian Security Information: DSA-3132 (Google Search)
http://www.debian.org/security/2015/dsa-3132
https://security.gentoo.org/glsa/201504-01
RedHat Security Advisories: RHSA-2015:0046
http://rhn.redhat.com/errata/RHSA-2015-0046.html
RedHat Security Advisories: RHSA-2015:0047
http://rhn.redhat.com/errata/RHSA-2015-0047.html
http://www.securitytracker.com/id/1031533
http://www.securitytracker.com/id/1031534
http://secunia.com/advisories/62237
http://secunia.com/advisories/62242
http://secunia.com/advisories/62250
http://secunia.com/advisories/62253
http://secunia.com/advisories/62259
http://secunia.com/advisories/62273
http://secunia.com/advisories/62274
http://secunia.com/advisories/62283
http://secunia.com/advisories/62293
http://secunia.com/advisories/62304
http://secunia.com/advisories/62313
http://secunia.com/advisories/62315
http://secunia.com/advisories/62316
http://secunia.com/advisories/62418
http://secunia.com/advisories/62446
http://secunia.com/advisories/62657
http://secunia.com/advisories/62790
SuSE Security Announcement: SUSE-SU-2015:0171 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
SuSE Security Announcement: SUSE-SU-2015:0173 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
SuSE Security Announcement: SUSE-SU-2015:0180 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
SuSE Security Announcement: openSUSE-SU-2015:0077 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
SuSE Security Announcement: openSUSE-SU-2015:0133 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
SuSE Security Announcement: openSUSE-SU-2015:0192 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.ubuntu.com/usn/USN-2460-1
XForce ISS Database: firefox-cve20148634-code-exec(99955)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99955
Common Vulnerability Exposure (CVE) ID: CVE-2014-8638
BugTraq ID: 72047
http://www.securityfocus.com/bid/72047
XForce ISS Database: firefox-cve20148638-csrf(99958)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99958
Common Vulnerability Exposure (CVE) ID: CVE-2014-8639
BugTraq ID: 72046
http://www.securityfocus.com/bid/72046
XForce ISS Database: firefox-cve20148639-session-hijacking(99959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99959
Common Vulnerability Exposure (CVE) ID: CVE-2014-8641
BugTraq ID: 72044
http://www.securityfocus.com/bid/72044
XForce ISS Database: firefox-cve20148641-dos(99961)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99961
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.