![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.70989 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu USN-1251-1 (firefox) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to firefox announced via advisory USN-1251-1. Details: It was discovered that CVE-2011-3004, which addressed possible privilege escalation in addons, also affected Firefox 3.6. An attacker could potentially exploit Firefox when an add-on was installed that used loadSubscript in vulnerable ways. (CVE-2011-3647) Yosuke Hasegawa discovered that the Mozilla browser engine mishandled invalid sequences in the Shift-JIS encoding. A malicious website could possibly use this flaw this to steal data or inject malicious scripts into web content. (CVE-2011-3648) Marc Schoenefeld discovered that using Firebug to profile a JavaScript file with many functions would cause Firefox to crash. An attacker might be able to exploit this without using the debugging APIs which would potentially allow an attacker to remotely crash the browser. (CVE-2011-3650) Solution: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: firefox 3.6.24+build2+nobinonly-0ubuntu0.10.10.1 xulrunner-1.9.2 1.9.2.24+build2+nobinonly-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: firefox 3.6.24+build2+nobinonly-0ubuntu0.10.04.1 xulrunner-1.9.2 1.9.2.24+build2+nobinonly-0ubuntu0.10.04.1 http://www.securityspace.com/smysecure/catid.html?in=USN-1251-1 CVSS Score: 9.3 CVSS Vector: AV:L/AC:H/Au:NR/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-3004 http://www.mandriva.com/security/advisories?name=MDVSA-2011:141 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14121 Common Vulnerability Exposure (CVE) ID: CVE-2011-3647 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13550 http://www.redhat.com/support/errata/RHSA-2011-1439.html SuSE Security Announcement: SUSE-SU-2011:1256 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html Common Vulnerability Exposure (CVE) ID: CVE-2011-3648 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14212 Common Vulnerability Exposure (CVE) ID: CVE-2011-3650 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13870 |
Copyright | Copyright (c) 2012 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |