Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html http://www.vuxml.org/freebsd/c223b00d-e272-11df-8e32-000f20797ede.html
Insight
The following packages are affected:
firefox
libxul
linux-firefox
linux-firefox-devel
linux-seamonkey
linux-thunderbird
seamonkey
thunderbird
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to
nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
Severity
Classification
-
CVE CVE-2010-3765 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities