Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70989
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1251-1 (firefox)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to firefox
announced via advisory USN-1251-1.

Details:

It was discovered that CVE-2011-3004, which addressed possible privilege
escalation in addons, also affected Firefox 3.6. An attacker could
potentially exploit Firefox when an add-on was installed that used
loadSubscript in vulnerable ways. (CVE-2011-3647)

Yosuke Hasegawa discovered that the Mozilla browser engine mishandled
invalid sequences in the Shift-JIS encoding. A malicious website could
possibly use this flaw this to steal data or inject malicious scripts into
web content. (CVE-2011-3648)

Marc Schoenefeld discovered that using Firebug to profile a JavaScript file
with many functions would cause Firefox to crash. An attacker might be able
to exploit this without using the debugging APIs which would potentially
allow an attacker to remotely crash the browser. (CVE-2011-3650)

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
firefox 3.6.24+build2+nobinonly-0ubuntu0.10.10.1
xulrunner-1.9.2 1.9.2.24+build2+nobinonly-0ubuntu0.10.10.1

Ubuntu 10.04 LTS:
firefox 3.6.24+build2+nobinonly-0ubuntu0.10.04.1
xulrunner-1.9.2 1.9.2.24+build2+nobinonly-0ubuntu0.10.04.1

http://www.securityspace.com/smysecure/catid.html?in=USN-1251-1

CVSS Score:
9.3

CVSS Vector:
AV:L/AC:H/Au:NR/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3004
http://www.mandriva.com/security/advisories?name=MDVSA-2011:141
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14121
Common Vulnerability Exposure (CVE) ID: CVE-2011-3647
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13550
http://www.redhat.com/support/errata/RHSA-2011-1439.html
SuSE Security Announcement: SUSE-SU-2011:1256 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html
Common Vulnerability Exposure (CVE) ID: CVE-2011-3648
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14212
Common Vulnerability Exposure (CVE) ID: CVE-2011-3650
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13870
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.