Summary
This host is installed with Mozilla firefox/thunderbird/seamonkey and is prone to clickjacking vulnerability.
Impact
Successful exploitation could allow attackers to gain sensitive information or bypass certain security restrictions.
Impact Level: Application
Solution
Upgrade to Mozilla Firefox version 14.0 or ESR version 10.0.6 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.11 or later,
http://www.mozilla.org/projects/seamonkey/
Upgrade to Thunderbird version to 14.0 or ESR 10.0.6 or later, http://www.mozilla.org/en-US/thunderbird/
Insight
The certificate warning functionality in
browser/components/certerror/content/aboutCertError.xhtml fails to handle attempted clickjacking of the 'about:certerror' page, allowing man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element
Affected
SeaMonkey version before 2.10
Thunderbird version 5.0 through 12.0
Mozilla Firefox version 4.x through 12.0
Thunderbird ESR version 10.x before 10.0.6
Mozilla Firefox ESR version 10.x before 10.0.6 on Mac OS X
References
Severity
Classification
-
CVE CVE-2012-1964 -
CVSS Base Score: 4.0
AV:N/AC:H/Au:N/C:P/I:P/A:N
Related Vulnerabilities
- Adobe Reader 'file://' URL Information Disclosure Vulnerability Feb07 (Linux)
- Apple Safari Multiple Memory Corruption Vulnerabilities-01 Aug14 (Mac OS X)
- Asterisk CIDR Notation in Access Rule Remote Security Bypass Vulnerability
- Apple Safari JavaScript Implementation Information Disclosure Vulnerability (Mac OS X)
- APC PowerChute Business Edition Unspecified Cross Site Scripting Vulnerability