Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52111
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2005:386
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2005:386.

Mozilla is an open source Web browser, advanced email and newsgroup client,
IRC chat client, and HTML editor.

Vladimir V. Perepelitsa discovered a bug in the way Mozilla handles
anonymous functions during regular expression string replacement. It is
possible for a malicious web page to capture a random block of browser
memory. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2005-0989 to this issue.

Doron Rosenberg discovered a bug in the way Mozilla displays pop-up
windows. If a user choses to open a pop-up window whose URL is malicious
javascript, the script will be executed with elevated privileges.
(CVE-2005-1153)

A bug was found in the way Mozilla handles the javascript global scope for
a window. It is possible for a malicious web page to define a global
variable known to be used by a different site, allowing malicious code to
be executed in the context of the site. (CVE-2005-1154)

Michael Krax discovered a bug in the way Mozilla handles favicon links. A
malicious web page can programatically define a favicon link tag as
javascript, executing arbitrary javascript with elevated privileges.
(CVE-2005-1155)

Michael Krax discovered a bug in the way Mozilla installed search plugins.
If a user chooses to install a search plugin from a malicious site, the new
plugin could silently overwrite an existing plugin. This could allow the
malicious plugin to execute arbitrary code and stealm sensitive
information. (CVE-2005-1156 CVE-2005-1157)

A bug was found in the way Mozilla validated several XPInstall related
javascript objects. A malicious web page could pass other objects to the
XPInstall objects, resulting in the javascript interpreter jumping to
arbitrary locations in memory. (CVE-2005-1159)

A bug was found in the way the Mozilla privileged UI code handled DOM nodes
from the content window. A malicious web page could install malicious
javascript code or steal data requiring a user to do commonplace actions
such as clicking a link or opening the context menu. (CVE-2005-1160)

Users of Mozilla are advised to upgrade to this updated package which
contains Mozilla version 1.7.7 to correct these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2005-386.html
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.7

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-0989
BugTraq ID: 12988
http://www.securityfocus.com/bid/12988
BugTraq ID: 15495
http://www.securityfocus.com/bid/15495
http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml
HPdes Security Advisory: HPSBUX01133
HPdes Security Advisory: SSRT5940
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100025
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11706
http://www.redhat.com/support/errata/RHSA-2005-383.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.redhat.com/support/errata/RHSA-2005-386.html
http://www.redhat.com/support/errata/RHSA-2005-601.html
SCO Security Bulletin: SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://securitytracker.com/id?1013635
http://securitytracker.com/id?1013643
http://secunia.com/advisories/14820
http://secunia.com/advisories/14821
http://secunia.com/advisories/19823
SuSE Security Announcement: SUSE-SA:2006:022 (Google Search)
http://www.novell.com/linux/security/advisories/2006_04_25.html
Common Vulnerability Exposure (CVE) ID: CVE-2005-1153
14938
http://secunia.com/advisories/14938
14992
http://secunia.com/advisories/14992
15495
GLSA-200504-18
RHSA-2005:383
RHSA-2005:384
RHSA-2005:386
SCOSA-2005.49
http://www.mozilla.org/security/announce/mfsa2005-35.html
https://bugzilla.mozilla.org/show_bug.cgi?id=289204
oval:org.mitre.oval:def:100023
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100023
oval:org.mitre.oval:def:9584
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9584
Common Vulnerability Exposure (CVE) ID: CVE-2005-1154
13230
http://www.securityfocus.com/bid/13230
http://www.mozilla.org/security/announce/mfsa2005-36.html
https://bugzilla.mozilla.org/show_bug.cgi?id=289675
oval:org.mitre.oval:def:100022
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100022
oval:org.mitre.oval:def:10339
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10339
Common Vulnerability Exposure (CVE) ID: CVE-2005-1155
13216
http://www.securityfocus.com/bid/13216
VU#973309
http://www.kb.cert.org/vuls/id/973309
http://www.mikx.de/firelinking/
http://www.mozilla.org/security/announce/mfsa2005-37.html
https://bugzilla.mozilla.org/show_bug.cgi?id=290036
oval:org.mitre.oval:def:100021
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100021
oval:org.mitre.oval:def:10655
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10655
Common Vulnerability Exposure (CVE) ID: CVE-2005-1156
1013745
http://securitytracker.com/id?1013745
13211
http://www.securityfocus.com/bid/13211
14996
http://secunia.com/advisories/14996
http://www.mikx.de/firesearching/
http://www.mozilla.org/security/announce/mfsa2005-38.html
https://bugzilla.mozilla.org/show_bug.cgi?id=290037
mozilla-plugin-xss(20125)
https://exchange.xforce.ibmcloud.com/vulnerabilities/20125
oval:org.mitre.oval:def:100020
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100020
oval:org.mitre.oval:def:11230
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11230
Common Vulnerability Exposure (CVE) ID: CVE-2005-1157
oval:org.mitre.oval:def:9961
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9961
Common Vulnerability Exposure (CVE) ID: CVE-2005-1159
1013742
http://securitytracker.com/id?1013742
1013743
http://securitytracker.com/id?1013743
13232
http://www.securityfocus.com/bid/13232
19823
RHSA-2005:601
SUSE-SA:2006:022
http://www.mozilla.org/security/announce/mfsa2005-40.html
https://bugzilla.mozilla.org/show_bug.cgi?id=290162
mozilla-installtrigger-command-execution(20123)
https://exchange.xforce.ibmcloud.com/vulnerabilities/20123
oval:org.mitre.oval:def:100018
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100018
oval:org.mitre.oval:def:10629
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10629
Common Vulnerability Exposure (CVE) ID: CVE-2005-1160
13233
http://www.securityfocus.com/bid/13233
http://www.mozilla.org/security/announce/mfsa2005-41.html
https://bugzilla.mozilla.org/show_bug.cgi?id=289074
https://bugzilla.mozilla.org/show_bug.cgi?id=289083
https://bugzilla.mozilla.org/show_bug.cgi?id=289961
oval:org.mitre.oval:def:100017
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017
oval:org.mitre.oval:def:11291
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.