Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | |||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.71709 |
Kategorie: | Ubuntu Local Security Checks |
Titel: | Ubuntu USN-1430-1 (firefox) |
Zusammenfassung: | NOSUMMARY |
Beschreibung: | Description: The remote host is missing an update to firefox announced via advisory USN-1430-1. Details: Bob Clary, Christian Holler, Brian Hackett, Bobby Holley, Gary Kwong, Hilary Hall, Honza Bambas, Jesse Ruderman, Julian Seward, and Olli Pettay discovered memory safety issues affecting Firefox. If the user were tricked into opening a specially crafted page, an attacker could exploit these to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2012-0467, CVE-2012-0468) Aki Helin discovered a use-after-free vulnerability in XPConnect. An attacker could potentially exploit this to execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2012-0469) Atte Kettunen discovered that invalid frees cause heap corruption in gfxImageSurface. If a user were tricked into opening a malicious Scalable Vector Graphics (SVG) image file, an attacker could exploit these to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2012-0470) Anne van Kesteren discovered a potential cross-site scripting (XSS) vulnerability via multibyte content processing errors. With cross-site scripting vulnerabilities, if a user were tricked into viewing a specially crafted page, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. (CVE-2012-0471) Matias Juntunen discovered a vulnerability in Firefox's WebGL implementation that potentially allows the reading of illegal video memory. An attacker could possibly exploit this to cause a denial of service via application crash. (CVE-2012-0473) Jordi Chancel, Eddy Bordi, and Chris McGowen discovered that Firefox allowed the address bar to display a different website than the one the user was visiting. This could potentially leave the user vulnerable to cross-site scripting (XSS) attacks. With cross-site scripting vulnerabilities, if a user were tricked into viewing a specially crafted page, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. (CVE-2012-0474) Simone Fabiano discovered that Firefox did not always send correct origin headers when connecting to an IPv6 websites. An attacker could potentially use this to bypass intended access controls. (CVE-2012-0475) Masato Kinugawa discovered that cross-site scripting (XSS) injection is possible during the decoding of ISO-2022-KR and ISO-2022-CN character sets. With cross-site scripting vulnerabilities, if a user were tricked into viewing a specially crafted page, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. (CVE-2012-0477) It was discovered that certain images rendered using WebGL could cause Firefox to crash. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2012-0478) Mateusz Jurczyk discovered an off-by-one error in the OpenType Sanitizer. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. (CVE-2011-3062) Daniel Divricean discovered a defect in the error handling of JavaScript errors can potentially leak the file names and location of JavaScript files on a server. This could potentially lead to inadvertent information disclosure and a vector for further attacks. (CVE-2011-1187) Jeroen van der Gun discovered a vulnerability in the way Firefox handled RSS and Atom feeds. Invalid RSS or ATOM content loaded over HTTPS caused the location bar to be updated with the address of this content, while the main window still displays the previously loaded content. An attacker could potentially exploit this vulnerability to conduct phishing attacks. (CVE-2012-0479) Solution: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: firefox 12.0+build1-0ubuntu0.11.10.1 Ubuntu 11.04: firefox 12.0+build1-0ubuntu0.11.04.1 Ubuntu 10.04 LTS: firefox 12.0+build1-0ubuntu0.10.04.1 https://secure1.securityspace.com/smysecure/catid.html?in=USN-1430-1 CVSS Score: 10.0 CVSS Vector: AV:L/AC:L/Au:NR/C:C/I:C/A:C |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2012-0467 BugTraq ID: 53223 http://www.securityfocus.com/bid/53223 Debian Security Information: DSA-2457 (Google Search) http://www.debian.org/security/2012/dsa-2457 Debian Security Information: DSA-2458 (Google Search) http://www.debian.org/security/2012/dsa-2458 Debian Security Information: DSA-2464 (Google Search) http://www.debian.org/security/2012/dsa-2464 http://www.mandriva.com/security/advisories?name=MDVSA-2012:066 http://www.mandriva.com/security/advisories?name=MDVSA-2012:081 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17074 http://secunia.com/advisories/48920 http://secunia.com/advisories/48922 http://secunia.com/advisories/48972 http://secunia.com/advisories/49047 http://secunia.com/advisories/49055 Common Vulnerability Exposure (CVE) ID: CVE-2012-0468 BugTraq ID: 53221 http://www.securityfocus.com/bid/53221 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16771 Common Vulnerability Exposure (CVE) ID: CVE-2012-0469 BugTraq ID: 53220 http://www.securityfocus.com/bid/53220 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16734 Common Vulnerability Exposure (CVE) ID: CVE-2012-0470 BugTraq ID: 53225 http://www.securityfocus.com/bid/53225 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16989 Common Vulnerability Exposure (CVE) ID: CVE-2012-0471 BugTraq ID: 53219 http://www.securityfocus.com/bid/53219 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16961 Common Vulnerability Exposure (CVE) ID: CVE-2012-0473 BugTraq ID: 53231 http://www.securityfocus.com/bid/53231 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16113 Common Vulnerability Exposure (CVE) ID: CVE-2012-0474 BugTraq ID: 53228 http://www.securityfocus.com/bid/53228 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16107 Common Vulnerability Exposure (CVE) ID: CVE-2012-0475 BugTraq ID: 53230 http://www.securityfocus.com/bid/53230 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16279 XForce ISS Database: firefox-websocket-sec-bypass(75153) https://exchange.xforce.ibmcloud.com/vulnerabilities/75153 Common Vulnerability Exposure (CVE) ID: CVE-2012-0477 BugTraq ID: 53229 http://www.securityfocus.com/bid/53229 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16889 XForce ISS Database: firefox-iso2022kr-xss(75154) https://exchange.xforce.ibmcloud.com/vulnerabilities/75154 Common Vulnerability Exposure (CVE) ID: CVE-2012-0478 BugTraq ID: 53227 http://www.securityfocus.com/bid/53227 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16893 XForce ISS Database: firefox-teximage2d-dos(75155) https://exchange.xforce.ibmcloud.com/vulnerabilities/75155 Common Vulnerability Exposure (CVE) ID: CVE-2011-3062 http://osvdb.org/80740 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15488 http://www.securitytracker.com/id?1026877 http://secunia.com/advisories/48618 http://secunia.com/advisories/48691 http://secunia.com/advisories/48763 XForce ISS Database: chrome-sanitizer-code-exec(74412) https://exchange.xforce.ibmcloud.com/vulnerabilities/74412 Common Vulnerability Exposure (CVE) ID: CVE-2011-1187 BugTraq ID: 46785 http://www.securityfocus.com/bid/46785 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14369 http://www.vupen.com/english/advisories/2011/0628 XForce ISS Database: google-unspecified-info-disc(65951) https://exchange.xforce.ibmcloud.com/vulnerabilities/65951 Common Vulnerability Exposure (CVE) ID: CVE-2012-0479 BugTraq ID: 53224 http://www.securityfocus.com/bid/53224 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17011 XForce ISS Database: firefox-rss-spoofing(75156) https://exchange.xforce.ibmcloud.com/vulnerabilities/75156 |
Copyright | Copyright (c) 2012 E-Soft Inc. http://www.securityspace.com |
Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |