RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
BID:41824
Info
RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
| Bugtraq ID: | 41824 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2010 12:00AM |
| Updated: | Jul 26 2010 09:45PM |
| Credit: | Jesse Ruderman, Ehsan Akhgari, Mats Palmgren, Igor Bukanov, Gary Kwong, Tobias Markus, Daniel Holbert, David Anderson, Johnny Stenback, regenrecht, J23, moz_bug_r_a4, Aki Helin, Yosuke Hasegawa, Vladimir Vukicevic, O. Andersen, Chris Evans, and Soroush Dal |
| Vulnerable: |
RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Mozilla Thunderbird 3.0.5 Mozilla Thunderbird 3.0.4 Mozilla Thunderbird 3.0.2 Mozilla Thunderbird 3.0.1 Mozilla Thunderbird 3.0 Mozilla SeaMonkey 2.0.5 Mozilla SeaMonkey 2.0.4 Mozilla SeaMonkey 2.0.3 Mozilla SeaMonkey 2.0.2 Mozilla SeaMonkey 2.0.1 Mozilla SeaMonkey 2.0 Mozilla Firefox 3.6.4 Mozilla Firefox 3.6.3 Mozilla Firefox 3.6.2 Mozilla Firefox 3.6.2 Mozilla Firefox 3.5.10 Mozilla Firefox 3.5.9 Mozilla Firefox 3.5.8 Mozilla Firefox 3.5.7 Mozilla Firefox 3.5.6 Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.6 |
| Not Vulnerable: |
Mozilla Thunderbird 3.1.1 Mozilla Thunderbird 3.0.6 Mozilla SeaMonkey 2.0.6 Mozilla Firefox 3.6.7 Mozilla Firefox 3.5.11 |
Discussion
RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
The Mozilla Foundation has released 14 security advisories specifying vulnerabilities in Mozilla Firefox, Thunderbird, and SeaMonkey.
These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, crash affected applications, elevate privileges, and disclose potentially sensitive information; other attacks may also be possible.
These issues are fixed in:
Firefox 3.6.7
Firefox 3.5.11
Thunderbird 3.0.6
Thunderbird 3.1.1
SeaMonkey 2.0.6
This BID is being retired. The following individual records exist to better document the issues:
41842 Mozilla Firefox and SeaMonkey Plugin Parameters Buffer Overflow Vulnerability
41845 Mozilla Firefox and SeaMonkey 'NodeIterator' Use-After-Free Remote Code Execution Vulnerability
41849 Mozilla Firefox and SeaMonkey DOM Cloning Remote Code Execution Vulnerability
41852 Mozilla Firefox, Thunderbird and SeaMonkey CSS Values Integer Overflow Vulnerability
41853 Mozilla Firefox, Thunderbird, and SeaMonkey 'nsTreeSelection' Remote Code Execution Vulnerability
41859 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1211 Remote Memory Corruption Vulnerability
41860 Multiple Mozilla Products Script Filename Cross Domain Information Disclosure Vulnerability
41865 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1212 Remote Memory Corruption Vulnerability
41866 Mozilla Firefox and Thunderbird Character Mapping Security Weakness
41868 Mozilla Firefox and Thunderbird 'SJOW' Privilege Escalation Vulnerability
41871 Multiple Mozilla Products 'importScripts()' Method Cross Domain Information Disclosure Vulnerability
41872 Multiple Mozilla Products CSS Selectors Cross Domain Information Disclosure Vulnerability
41878 Mozilla Firefox and Thunderbird Canvas Element Cross Domain Information Disclosure Vulnerability
41968 Mozilla Firefox and Sea Monkey Location Bar Spoofing Vulnerability
The Mozilla Foundation has released 14 security advisories specifying vulnerabilities in Mozilla Firefox, Thunderbird, and SeaMonkey.
These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, crash affected applications, elevate privileges, and disclose potentially sensitive information; other attacks may also be possible.
These issues are fixed in:
Firefox 3.6.7
Firefox 3.5.11
Thunderbird 3.0.6
Thunderbird 3.1.1
SeaMonkey 2.0.6
This BID is being retired. The following individual records exist to better document the issues:
41842 Mozilla Firefox and SeaMonkey Plugin Parameters Buffer Overflow Vulnerability
41845 Mozilla Firefox and SeaMonkey 'NodeIterator' Use-After-Free Remote Code Execution Vulnerability
41849 Mozilla Firefox and SeaMonkey DOM Cloning Remote Code Execution Vulnerability
41852 Mozilla Firefox, Thunderbird and SeaMonkey CSS Values Integer Overflow Vulnerability
41853 Mozilla Firefox, Thunderbird, and SeaMonkey 'nsTreeSelection' Remote Code Execution Vulnerability
41859 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1211 Remote Memory Corruption Vulnerability
41860 Multiple Mozilla Products Script Filename Cross Domain Information Disclosure Vulnerability
41865 Mozilla Firefox, Thunderbird, and SeaMonkey CVE-2010-1212 Remote Memory Corruption Vulnerability
41866 Mozilla Firefox and Thunderbird Character Mapping Security Weakness
41868 Mozilla Firefox and Thunderbird 'SJOW' Privilege Escalation Vulnerability
41871 Multiple Mozilla Products 'importScripts()' Method Cross Domain Information Disclosure Vulnerability
41872 Multiple Mozilla Products CSS Selectors Cross Domain Information Disclosure Vulnerability
41878 Mozilla Firefox and Thunderbird Canvas Element Cross Domain Information Disclosure Vulnerability
41968 Mozilla Firefox and Sea Monkey Location Bar Spoofing Vulnerability
Exploit / POC
RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Solution / Fix
RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
Solution:
New versions of Firefox, SeaMonkey, and Thunderbird are available to address these issues. Most Mozilla applications have self-updating features that may be used to download and install fixes.
Please see the referenced advisories for information on obtaining and applying fixes.
Solution:
New versions of Firefox, SeaMonkey, and Thunderbird are available to address these issues. Most Mozilla applications have self-updating features that may be used to download and install fixes.
Please see the referenced advisories for information on obtaining and applying fixes.
References
RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-34 Through -47 Multiple Vulnerabilities
References:
References:
- Mozilla Foundation Security Advisory 2010-34 (Mozilla)
- Mozilla Foundation Security Advisory 2010-35 (Mozilla)
- Mozilla Foundation Security Advisory 2010-36 (Mozilla)
- Mozilla Foundation Security Advisory 2010-37 (Mozilla)
- Mozilla Foundation Security Advisory 2010-38 (Mozilla)
- Mozilla Foundation Security Advisory 2010-39 (Mozilla)
- Mozilla Foundation Security Advisory 2010-40 (Mozilla)
- Mozilla Foundation Security Advisory 2010-42 (Mozilla)
- Mozilla Foundation Security Advisory 2010-43 (Mozilla)
- Mozilla Foundation Security Advisory 2010-44 (Mozilla)
- Mozilla Foundation Security Advisory 2010-45 (Mozilla)
- Mozilla Foundation Security Advisory 2010-46 (Mozilla)
- Mozilla Foundation Security Advisory 2010-47 (Mozilla)