Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.880726
Categoría:CentOS Local Security Checks
Título:CentOS Update for firefox CESA-2009:1430 centos5 i386
Resumen:The remote host is missing an update for the 'firefox'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'firefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074,
CVE-2009-3075)

A use-after-free flaw was found in Firefox. An attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code with the
privileges of the user running Firefox. (CVE-2009-3077)

A flaw was found in the way Firefox handles malformed JavaScript. A website
with an object containing malicious JavaScript could execute that
JavaScript with the privileges of the user running Firefox. (CVE-2009-3079)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3076)

A flaw was found in the way Firefox displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

A flaw was found in the way Firefox displays certain Unicode characters. An
attacker could use this flaw to conceal a malicious URL, possibly tricking
a user into believing they are viewing a trusted site. (CVE-2009-3078)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.14. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.14, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.

Affected Software/OS:
firefox on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-2654
BugTraq ID: 35803
http://www.securityfocus.com/bid/35803
Bugtraq: 20090724 URL spoofing bug involving Firefox's error pages and document.write (Google Search)
http://www.securityfocus.com/archive/1/505242/30/0/threaded
Bugtraq: 20090727 Re: URL spoofing bug involving Firefox's error pages and document.write (Google Search)
http://www.securityfocus.com/archive/1/505265
Debian Security Information: DSA-1873 (Google Search)
http://www.debian.org/security/2009/dsa-1873
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00198.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00261.html
http://es.geocities.com/jplopezy/firefoxspoofing.html
http://osvdb.org/56717
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9686
http://www.redhat.com/support/errata/RHSA-2009-1430.html
http://www.redhat.com/support/errata/RHSA-2009-1431.html
http://www.redhat.com/support/errata/RHSA-2009-1432.html
http://www.securitytracker.com/id?1022603
http://secunia.com/advisories/36001
http://secunia.com/advisories/36126
http://secunia.com/advisories/36141
http://secunia.com/advisories/36435
http://secunia.com/advisories/36669
http://secunia.com/advisories/36670
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1
https://usn.ubuntu.com/811-1/
http://www.vupen.com/english/advisories/2009/2006
http://www.vupen.com/english/advisories/2009/2142
Common Vulnerability Exposure (CVE) ID: CVE-2009-3070
36343
http://www.securityfocus.com/bid/36343
36670
36671
http://secunia.com/advisories/36671
36692
http://secunia.com/advisories/36692
37098
http://secunia.com/advisories/37098
DSA-1885
http://www.debian.org/security/2009/dsa-1885
RHSA-2009:1430
SUSE-SA:2009:048
http://www.novell.com/linux/security/advisories/2009_48_firefox.html
http://www.mozilla.org/security/announce/2009/mfsa2009-47.html
https://bugzilla.mozilla.org/show_bug.cgi?id=430569
https://bugzilla.mozilla.org/show_bug.cgi?id=437565
https://bugzilla.mozilla.org/show_bug.cgi?id=465651
oval:org.mitre.oval:def:11702
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11702
oval:org.mitre.oval:def:6073
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6073
Common Vulnerability Exposure (CVE) ID: CVE-2009-3071
https://bugzilla.mozilla.org/show_bug.cgi?id=490196
https://bugzilla.mozilla.org/show_bug.cgi?id=493649
https://bugzilla.mozilla.org/show_bug.cgi?id=495444
https://bugzilla.mozilla.org/show_bug.cgi?id=502017
oval:org.mitre.oval:def:10698
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10698
oval:org.mitre.oval:def:5905
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5905
Common Vulnerability Exposure (CVE) ID: CVE-2009-3072
36669
38977
http://secunia.com/advisories/38977
39001
http://secunia.com/advisories/39001
ADV-2010-0648
http://www.vupen.com/english/advisories/2010/0648
ADV-2010-0650
http://www.vupen.com/english/advisories/2010/0650
RHSA-2009:1431
RHSA-2009:1432
RHSA-2010:0153
http://www.redhat.com/support/errata/RHSA-2010-0153.html
RHSA-2010:0154
http://www.redhat.com/support/errata/RHSA-2010-0154.html
SUSE-SR:2010:013
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
USN-915-1
http://www.ubuntu.com/usn/USN-915-1
http://www.mozilla.org/security/announce/2010/mfsa2010-07.html
https://bugzilla.mozilla.org/show_bug.cgi?id=494283
https://bugzilla.mozilla.org/show_bug.cgi?id=501900
https://bugzilla.mozilla.org/show_bug.cgi?id=508074
oval:org.mitre.oval:def:10349
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10349
oval:org.mitre.oval:def:6315
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6315
Common Vulnerability Exposure (CVE) ID: CVE-2009-3074
firefox-javascript-code-exec(53157)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53157
https://bugzilla.mozilla.org/show_bug.cgi?id=467493
oval:org.mitre.oval:def:6053
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6053
oval:org.mitre.oval:def:9444
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9444
Common Vulnerability Exposure (CVE) ID: CVE-2009-3075
https://bugzilla.mozilla.org/show_bug.cgi?id=441714
https://bugzilla.mozilla.org/show_bug.cgi?id=505305
mozilla-javascript-engine-code-exec(53158)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53158
oval:org.mitre.oval:def:11365
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11365
oval:org.mitre.oval:def:5717
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5717
Common Vulnerability Exposure (CVE) ID: CVE-2009-3076
1022877
http://www.securitytracker.com/id?1022877
http://www.mozilla.org/security/announce/2009/mfsa2009-48.html
https://bugzilla.mozilla.org/show_bug.cgi?id=326628
https://bugzilla.mozilla.org/show_bug.cgi?id=509413
oval:org.mitre.oval:def:6140
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6140
oval:org.mitre.oval:def:9306
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9306
Common Vulnerability Exposure (CVE) ID: CVE-2009-3077
http://www.mozilla.org/security/announce/2009/mfsa2009-49.html
https://bugzilla.mozilla.org/show_bug.cgi?id=506871
oval:org.mitre.oval:def:10730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10730
oval:org.mitre.oval:def:5606
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5606
Common Vulnerability Exposure (CVE) ID: CVE-2009-3078
1022875
http://www.securitytracker.com/id?1022875
http://www.mozilla.org/security/announce/2009/mfsa2009-50.html
https://bugzilla.mozilla.org/show_bug.cgi?id=453827
oval:org.mitre.oval:def:10871
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10871
oval:org.mitre.oval:def:5418
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5418
Common Vulnerability Exposure (CVE) ID: CVE-2009-3079
1022873
http://www.securitytracker.com/id?1022873
36757
http://secunia.com/advisories/36757
DSA-1886
http://www.debian.org/security/2009/dsa-1886
http://www.mozilla.org/security/announce/2009/mfsa2009-51.html
https://bugzilla.mozilla.org/show_bug.cgi?id=454363
oval:org.mitre.oval:def:10390
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10390
oval:org.mitre.oval:def:6250
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6250
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.