Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.72083
Category:Mandrake Local Security Checks
Title:Mandriva Security Advisory MDVSA-2011:192 (mozilla)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to mozilla
announced via advisory MDVSA-2011:192.

Security issues were identified and fixed in mozilla firefox and
thunderbird:

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and
SeaMonkey 2.5 does not properly interact with DOMAttrModified event
handlers, which allows remote attackers to cause a denial of service
(out-of-bounds memory access) or possibly have unspecified other
impact via vectors involving removal of SVG elements (CVE-2011-3658).

Multiple unspecified vulnerabilities in the browser engine in Mozilla
Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey
before 2.6 allow remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute arbitrary
code via vectors that trigger a compartment mismatch associated with
the nsDOMMessageEvent::GetData function, and unknown other vectors
(CVE-2011-3660).

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0
through 8.0, and SeaMonkey before 2.6, allows remote attackers to
cause a denial of service (application crash) or possibly execute
arbitrary code via crafted JavaScript (CVE-2011-3661).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and
SeaMonkey before 2.6 allow remote attackers to capture keystrokes
entered on a web page by using SVG animation accessKey events within
that web page (CVE-2011-3663).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and
SeaMonkey before 2.6 allow remote attackers to cause a denial of
service (application crash) or possibly have unspecified other impact
via an Ogg VIDEO element that is not properly handled after scaling
(CVE-2011-3665).

Affected: 2011.

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:192

Risk factor : High

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3658
http://www.mandriva.com/security/advisories?name=MDVSA-2011:192
http://www.mandriva.com/security/advisories?name=MDVSA-2012:031
http://osvdb.org/77953
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14664
http://www.securitytracker.com/id?1026445
http://www.securitytracker.com/id?1026446
http://www.securitytracker.com/id?1026447
http://secunia.com/advisories/47302
http://secunia.com/advisories/47334
http://secunia.com/advisories/48495
http://secunia.com/advisories/48553
http://secunia.com/advisories/48823
http://secunia.com/advisories/49055
SuSE Security Announcement: openSUSE-SU-2012:0007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.html
SuSE Security Announcement: openSUSE-SU-2012:0039 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.html
SuSE Security Announcement: openSUSE-SU-2012:0417 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-03/msg00042.html
http://www.ubuntu.com/usn/USN-1401-1
XForce ISS Database: firefox-domattrmodified-code-exec(71910)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71910
Common Vulnerability Exposure (CVE) ID: CVE-2011-3660
http://osvdb.org/77952
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14226
XForce ISS Database: firefox-safety-bugs-ce(71908)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71908
Common Vulnerability Exposure (CVE) ID: CVE-2011-3661
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14424
XForce ISS Database: firefox-yarr-dos(71909)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71909
Common Vulnerability Exposure (CVE) ID: CVE-2011-3663
http://osvdb.org/77954
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14739
XForce ISS Database: firefox-svg-animation-info-disc(71911)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71911
Common Vulnerability Exposure (CVE) ID: CVE-2011-3665
http://osvdb.org/77956
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14640
XForce ISS Database: firefox-ogg-dos(71913)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71913
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.