Summary
This host is installed with Mozilla firefox/thunderbird/seamonkey and is prone to clickjacking vulnerability.
Impact
Successful exploitation could allow attackers to gain sensitive information or bypass certain security restrictions.
Impact Level: Application
Solution
Upgrade to Mozilla Firefox version 14.0 or ESR version 10.0.6 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.11 or later,
http://www.mozilla.org/projects/seamonkey/
Upgrade to Thunderbird version to 14.0 or ESR 10.0.6 or later, http://www.mozilla.org/en-US/thunderbird/
Insight
The certificate warning functionality in
browser/components/certerror/content/aboutCertError.xhtml fails to handle attempted clickjacking of the 'about:certerror' page, allowing man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element
Affected
SeaMonkey version before 2.10
Thunderbird version 5.0 through 12.0
Mozilla Firefox version 4.x through 12.0
Thunderbird ESR version 10.x before 10.0.6
Mozilla Firefox ESR version 10.x before 10.0.6 on Windows
References
Severity
Classification
-
CVE CVE-2012-1964 -
CVSS Base Score: 4.0
AV:N/AC:H/Au:N/C:P/I:P/A:N
Related Vulnerabilities
- Apple iTunes Insecure Permissions Privilege Escalation Vulnerability (Mac OS X)
- Adobe Flash Player Unspecified Cross-Site Scripting Vulnerability June-2011 (Linux)
- Adobe Reader Plugin Signature Bypass Vulnerability (Windows)
- Adobe Digital Edition Information Disclosure Vulnerability (Windows)
- Apple Safari 'Webkit' Multiple Vulnerabilities-01 Mar14 (Mac OS X)