Summary
The host is installed with Mozilla firefox/thunderbird/seamonkey and is prone to information disclosure vulnerability.
Impact
Successful exploitation will let attackers to get sensitive information.
Impact Level: Application
Solution
Upgrade to Mozilla Firefox version 3.6.27 or 7.0 or later For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.4 or later
http://www.mozilla.org/projects/seamonkey/
Upgrade to Thunderbird version to 3.1.18 or 7.0 or later http://www.mozilla.org/en-US/thunderbird/
Insight
The flaw is due to requests made using IPv6 syntax using XMLHttpRequest objects through a proxy may generate errors depending on proxy configuration for IPv6. The resulting error messages from the proxy may disclose sensitive data.
Affected
SeaMonkey version before 2.4
Thunderbird version before 3.1.18 and 5.0 through 6.0 Mozilla Firefox version before 3.6.26 and 4.x through 6.0
References
Severity
Classification
-
CVE CVE-2011-3670 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities