Summary
The host is installed with Mozilla firefox/thunderbird/seamonkey and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 3.6.28 or 11.0 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Upgrade to SeaMonkey version to 2.8 or later,
http://www.mozilla.org/projects/seamonkey/
Upgrade to Thunderbird version to 3.1.20 or 11 or later, http://www.mozilla.org/en-US/thunderbird/
Insight
The flaws are due to
- Multiple unspecified vulnerabilities in the browser engine.
- An improper implementation of the nsWindow failing to validate an instance after event dispatching.
- An error when handling 'javascript:'.
- A use-after-free error exists within the
'nsSMILTimeValueSpec::ConvertBetweenTimeContainers()' function.
- An improper implementation of SVG Filters.
Affected
SeaMonkey version before 2.8
Thunderbird ESR version 10.x before 10.0.3
Mozilla Firefox ESR version 10.x before 10.0.3
Thunderbird version before 3.1.20 and 5.0 through 10.0 Mozilla Firefox version before 3.6.28 and 4.x through 10.0
References
- http://secunia.com/advisories/48402
- http://www.mozilla.org/security/announce/2012/mfsa2012-13.html
- http://www.mozilla.org/security/announce/2012/mfsa2012-14.html
- http://www.mozilla.org/security/announce/2012/mfsa2012-16.html
- http://www.mozilla.org/security/announce/2012/mfsa2012-19.html
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-0455, CVE-2012-0456, CVE-2012-0457, CVE-2012-0458, CVE-2012-0461, CVE-2012-0463, CVE-2012-0464 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Active Perl Locale::Maketext Module Multiple Code Injection Vulnerabilities (Windows)
- Adobe AIR Multiple Vulnerabilities(APSB14-24)-(Windows)
- Adobe Air Multiple Vulnerabilities -01 August 12 (Mac OS X)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 May13 (Mac OS X)
- Adobe Acrobat Multiple Vulnerabilities-01 Dec14 (Windows)