| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801471 |
| Category: | General |
| Title: | Mozilla Products Multiple Cross-site Scripting Vulnerabilities (Windows) |
| Summary: | Check for the version of Mozilla Products |
| Description: | Overview: The host is installed with Mozilla Firefox/Seamonkey and is prone to multiple vulnerabilities. Vulnerability Insight: The flaw is due to an error in functions used by the 'Gopher parser' to convert text to HTML tags, could be exploited to turn text into executable JavaScript. Impact: Successful exploitation will let attackers to inject arbitrary web script or HTML via a crafted name of a file or directory on a Gopher server. Impact Level: Application Affected Software/OS: SeaMonkey version before 2.0.9 Firefox version before 3.5.14 and 3.6.x before 3.6.11 Fix: Upgrade to Firefox version 3.6.11 or 3.5.14 or later http://www.mozilla.com/en-US/firefox/all.html Upgrade to Seamonkey version 2.0.9 or later http://www.seamonkey-project.org/releases/ References: http://www.mozilla.org/security/announce/2010/mfsa2010-68.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-3177 Debian Security Information: DSA-2124 (Google Search) http://www.debian.org/security/2010/dsa-2124 http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html http://www.mandriva.com/security/advisories?name=MDVSA-2010:210 http://www.redhat.com/support/errata/RHSA-2010-0781.html http://www.redhat.com/support/errata/RHSA-2010-0782.html http://www.redhat.com/support/errata/RHSA-2010-0861.html http://www.ubuntu.com/usn/USN-997-1 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12202 http://secunia.com/advisories/42867 http://www.vupen.com/english/advisories/2011/0061 |
| Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|