Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
BID:43222
Info
Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
| Bugtraq ID: | 43222 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2010-3171 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Jan 07 2011 08:32PM |
| Credit: | Amit Klein |
| Vulnerable: |
Sun Solaris 11 Express Sun Solaris 10_x86 Sun Solaris 10_sparc Mozilla Firefox 3.6.8 Mozilla Firefox 3.6.6 Mozilla Firefox 3.6.4 Mozilla Firefox 3.5.10 Mozilla Firefox 4.0 Beta1 Mozilla Firefox 3.6.7 Mozilla Firefox 3.5.11 |
| Not Vulnerable: |
Mozilla Firefox 3.6.9 Mozilla Firefox 3.5.12 |
Discussion
Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
Mozilla Firefox is prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
Successful exploits will allow attackers to bypass the same-origin policy and obtain potentially sensitive information; other attacks are possible.
Mozilla Firefox is prone to a cross-domain information-disclosure vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
Successful exploits will allow attackers to bypass the same-origin policy and obtain potentially sensitive information; other attacks are possible.
Exploit / POC
Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability
References:
References:
- Mozilla Firefox Homepage (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- Multiple Vulnerabilities in Mozilla Firefox (Oracle)
- Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 (Amit Klein)