Executive Summary
| Informations | |||
|---|---|---|---|
| Name | MDVSA-2008:245 | First vendor Publication | 2008-12-17 |
| Vendor | Mandriva | Last vendor Modification | 2008-12-17 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox 3.x, version 3.0.5 (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5505, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5510, CVE-2008-5511, CVE-2008-5512, CVE-2008-5513). This update provides the latest Mozilla Firefox 3.x to correct these issues. |
Original Source
| Url : http://www.mandriva.com/security/advisories?name=MDVSA-2008:245 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls |
| CWE-399 | Resource Management Errors |
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| CWE-200 | Information Exposure |
| CWE-20 | Improper Input Validation |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:10443 | |||
| Oval ID: | oval:org.mitre.oval:def:10443 | ||
| Title: | Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies. | ||
| Description: | Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2008-5505 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9662 | |||
| Oval ID: | oval:org.mitre.oval:def:9662 | ||
| Title: | The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines. | ||
| Description: | The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2008-5510 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 51297 | Mozilla Firefox session-restore Data Restoration Same-origin Policy Bypass |
| 51296 | Mozilla Multiple Products XPCNativeWrappers Pollution JavaScript Privilege Es... |
| 51295 | Mozilla Multiple Products XBL Binding Unloaded Document XSS |
| 51294 | Mozilla Multiple Products CSS Parser Escaped Null Character Protection Mechan... |
| 51293 | Mozilla Multiple Products Whitespace / Control Character URL Handling Phishin... |
| 51292 | Mozilla Multiple Products window.onerror DOM API Same-origin Policy Bypass In... |
| 51291 | Mozilla Multiple Products XMLHttpRequest 302 Redirect Same-origin Policy Bypa... |
| 51290 | Mozilla Firefox XUL Persist Attribute User Privacy Restriction Bypass |
| 51287 | Mozilla Multiple Products Layout Engine FastAppendChar Function Memory Corrup... |
| 51286 | Mozilla Multiple Products Layout Engine Assertion Failure Remote DoS |
| 51285 | Mozilla Multiple Products Layout Engine nsEscapeHTML2 Overflow |
| 51284 | Mozilla Multiple Products Layout Engine PresShell::InitialReflow XUL iframe O... |

MDVSA-2008:245
(Critical)
(Medium)






