Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.mikx.de/fireflashing/
http://www.mikx.de/firescrolling/
http://www.mozilla.org/security/announce/mfsa2005-27.html http://www.vuxml.org/freebsd/cbfde1cd-87eb-11d9-aa18-0001020eed82.html
Insight
The following packages are affected:
firefox
mozilla
linux-mozilla
linux-mozilla-devel
netscape7
de-linux-mozillafirebird
el-linux-mozillafirebird
ja-linux-mozillafirebird-gtk1
ja-mozillafirebird-gtk2
linux-mozillafirebird
ru-linux-mozillafirebird
zhCN-linux-mozillafirebird
zhTW-linux-mozillafirebird
de-linux-netscape
de-netscape7
fr-linux-netscape
fr-netscape7
ja-linux-netscape
ja-netscape7
linux-netscape
linux-phoenix
mozilla+ipv6
mozilla-embedded
mozilla-firebird
mozilla-gtk1
mozilla-gtk2
mozilla-gtk
mozilla-thunderbird
phoenix
pt_BR-netscape7
CVE-2005-0527
Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load 'privileged content' into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka 'Firescrolling.'
Severity
Classification
-
CVE CVE-2005-0527 -
CVSS Base Score: 5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities