Summary
The host is installed with Mozilla Firefox/Seamonkey/Thunderbird and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to to cause a denial of service or execute arbitrary code.
Impact Level: Application
Solution
Upgrade to Firefox version 3.6.11 or 3.5.14 or later http://www.mozilla.com/en-US/firefox/all.html
Upgrade to Seamonkey version 2.0.9 or later
http://www.seamonkey-project.org/releases/
Upgrade to Thunderbird version 3.0.9 or 3.1.5 or later http://www.mozillamessaging.com/en-US/thunderbird/
Insight
The flaws are due to:
- A wildcard IP address in the 'subject&qts' Common Name field of an X.509 certificate.
- not properly setting the minimum key length for 'Diffie-Hellman Ephemeral' (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
- Passing an excessively long string to 'document.write' could cause text rendering routines to end up in an inconsistent state with sections of stack memory being overwritten with the string data.
- not properly handling certain modal calls made by 'javascript: URLs' in circumstances related to opening a new window and performing cross-domain navigation.
- an untrusted search path vulnerability.
- Use-after-free vulnerability in the nsBarProp function.
- error in 'LookupGetterOrSetter' function, which does not properly support 'window.__lookupGetter__ function' calls that lack arguments.
Affected
Seamonkey version prior to 2.0.9
Firefox version prior to 3.5.14 and 3.6.x before 3.6.11 Thunderbird version proior to 3.0.9 and 3.1.x before 3.1.5
References
Severity
Classification
-
CVE CVE-2010-3170, CVE-2010-3173, CVE-2010-3178, CVE-2010-3179, CVE-2010-3180, CVE-2010-3181, CVE-2010-3183 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Air Multiple Vulnerabilities - December12 (Mac OS X)
- Adobe Acrobat Multiple Vulnerabilities -01 Jan 13 (Mac OS X)
- Adobe AIR Security Bypass Vulnerability Jan14 (Mac OS X)
- Adobe Acrobat Multiple Unspecified Vulnerabilities - Mac OS X
- Adobe Flash Player Arbitrary Code Execution Vulnerability (Linux)