Executive Summary
| Informations | |||
|---|---|---|---|
| Name | MDVSA-2008:244 | First vendor Publication | 2008-12-17 |
| Vendor | Mandriva | Last vendor Modification | 2008-12-17 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox 2.x, version 2.0.0.19 (CVE-2008-5500, CVE-2008-5503, CVE-2008-5504, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5510, CVE-2008-5511, CVE-2008-5512, CVE-2008-5513). This update provides the latest Mozilla Firefox 2.x to correct these issues. |
Original Source
| Url : http://www.mandriva.com/security/advisories?name=MDVSA-2008:244 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls |
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| CWE-399 | Resource Management Errors |
| CWE-200 | Information Exposure |
| CWE-20 | Improper Input Validation |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:11423 | |||
| Oval ID: | oval:org.mitre.oval:def:11423 | ||
| Title: | The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings. | ||
| Description: | The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2008-5503 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9662 | |||
| Oval ID: | oval:org.mitre.oval:def:9662 | ||
| Title: | The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines. | ||
| Description: | The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2008-5510 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 51297 | Mozilla Firefox session-restore Data Restoration Same-origin Policy Bypass |
| 51296 | Mozilla Multiple Products XPCNativeWrappers Pollution JavaScript Privilege Es... |
| 51295 | Mozilla Multiple Products XBL Binding Unloaded Document XSS |
| 51294 | Mozilla Multiple Products CSS Parser Escaped Null Character Protection Mechan... |
| 51293 | Mozilla Multiple Products Whitespace / Control Character URL Handling Phishin... |
| 51292 | Mozilla Multiple Products window.onerror DOM API Same-origin Policy Bypass In... |
| 51291 | Mozilla Multiple Products XMLHttpRequest 302 Redirect Same-origin Policy Bypa... |
| 51289 | Mozilla Firefox Feed Preview JavaScript Privilege Escalation |
| 51288 | Mozilla Multiple Product loadBindingDocument Function XBL Binding Same-domain... |
| 51285 | Mozilla Multiple Products Layout Engine nsEscapeHTML2 Overflow |
| 51284 | Mozilla Multiple Products Layout Engine PresShell::InitialReflow XUL iframe O... |

MDVSA-2008:244
(Critical)
(High)
(Medium)
(Low)






