Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.15432
Categoría:Windows
Título:Mozilla/Firefox default installation file permission flaw
Resumen:The remote host is using Mozilla and/or Firefox, an alternative web browser.; The remote version of this software is prone to an improper file permission; setting.;; This flaw only exists if the browser is installed by the Mozilla Foundation; package management, thus this alert might be a false positive.;; A local attacker could overwrite arbitrary files or execute arbitrary code in; the context of the user running the browser.
Descripción:Summary:
The remote host is using Mozilla and/or Firefox, an alternative web browser.
The remote version of this software is prone to an improper file permission
setting.

This flaw only exists if the browser is installed by the Mozilla Foundation
package management, thus this alert might be a false positive.

A local attacker could overwrite arbitrary files or execute arbitrary code in
the context of the user running the browser.

Solution:
Update to the latest version of the software

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2004-0906
BugTraq ID: 11192
http://www.securityfocus.com/bid/11192
CERT/CC vulnerability note: VU#653160
http://www.kb.cert.org/vuls/id/653160
http://security.gentoo.org/glsa/glsa-200409-26.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11668
http://www.redhat.com/support/errata/RHSA-2005-323.html
http://secunia.com/advisories/12526/
SuSE Security Announcement: SUSE-SA:2004:036 (Google Search)
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
XForce ISS Database: mozilla-insecure-file-permissions(17375)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17375
CopyrightCopyright (C) 2004 David Maciejak

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.