Summary
The host is installed with Mozilla Firefox browser, that is prone to multiple vulnerabilities.
Impact
Successful exploitation could result in remote arbitrary code execution, spoofing attacks, sensitive information disclosure, and JavaScript code can be executed with the privileges of JAR's signer.
Impact Level: System
Solution
Upgrade to Firefox version 2.0.0.15
http://www.mozilla.com/en-US/firefox/all-older.html
Insight
Issues in browser are due to,
- multiple errors in the layout and JavaScript engines that can corrupt memory.
- error while handling unprivileged XUL documents that can be exploited to load chrome scripts from a fastload file via <script> elements.
- error in mozIJSSubScriptLoader.LoadScript function can bypass XPCNativeWrappers.
- error in block re-flow process, which can potentially lead to crash.
- error in processing file URLs contained within local directory listings.
- errors in the implementation of the Javascript same origin policy - errors in the verification of signed JAR files.
- improper implementation of file upload forms result in uploading specially crafted DOM Range and originalTarget elements.
- error in Java LiveConnect implementation.
- error in processing of Alt Names provided by peer.
- error in processing of windows URL shortcuts.
Affected
Firefox version prior to 2.0.0.15 on Windows.
References
- http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2806, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2810, CVE-2008-2811 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat and Reader PDF Handling Multiple Vulnerabilities (Windows)
- Adobe Acrobat and Reader PDF Handling Multiple Vulnerabilities (Linux)
- Adobe AIR Multiple Vulnerabilities-01 Dec13 (Windows)
- Adobe Flash Player 9.0.115.0 and earlier vulnerability (Lin)
- Adobe Acrobat Multiple Vulnerabilities - Windows