Summary
The host is installed with Mozilla Firefox/Seamonkey/Thunderbird is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to execute arbitrary code on the system or cause the browser to crash.
Impact Level: Application
Solution
Upgrade to Firefox version 3.0.19, 3.5.9, 3.6.2
http://www.mozilla.com/en-US/firefox/all.html
Upgrade to Seamonkey version 2.0.4
http://www.seamonkey-project.org/releases/
Insight
The flaws are due to:
- A dangling pointer flaw in the 'nsPluginArray window.navigator.plugins object' when user loads specially crafted HTML which allows to execute arbitrary code via unknown vectors.
- An error in loading a specially crafted applet, that converts a user mouse click into a 'drag-and-drop' action which allows to load a privileged 'chrome:' URL and execute arbitrary scripting code with privileges.
Affected
Seamonkey version prior to 2.0.4 and
Firefox version 3.0.x before 3.0.19, 3.5.x before 3.5.9, 3.6.x before 3.6.2
References
Severity
Classification
-
CVE CVE-2010-0177, CVE-2010-0178 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities