Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802170
Kategorie:General
Titel:Mozilla Firefox Memory Corruption and Integer Underflow Vulnerabilities (Windows)
Zusammenfassung:The host is installed with Mozilla Firefox and is prone to memory; corruption and integer underflow vulnerabilities.
Beschreibung:Summary:
The host is installed with Mozilla Firefox and is prone to memory
corruption and integer underflow vulnerabilities.

Vulnerability Insight:
The flaws are due to

- An integer underflow error exists within the Regular Expression engine
when evaluating certain regular expressions.

- An unspecified error can be exploited to corrupt memory.

Vulnerability Impact:
Successful exploitation allows remote attackers to execute arbitrary code
with the privileges of the user running the affected application. Failed
attempts may trigger a denial-of-service condition.

Affected Software/OS:
Mozilla Firefox 3.6.x before 3.6.23

Solution:
Upgrade to Firefox version 3.6.23 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 49845
BugTraq ID: 49809
Common Vulnerability Exposure (CVE) ID: CVE-2011-2996
http://www.mandriva.com/security/advisories?name=MDVSA-2011:139
http://www.mandriva.com/security/advisories?name=MDVSA-2011:140
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14064
SuSE Security Announcement: SUSE-SU-2011:1256 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html
Common Vulnerability Exposure (CVE) ID: CVE-2011-2998
Debian Security Information: DSA-2312 (Google Search)
http://www.debian.org/security/2011/dsa-2312
Debian Security Information: DSA-2313 (Google Search)
http://www.debian.org/security/2011/dsa-2313
Debian Security Information: DSA-2317 (Google Search)
http://www.debian.org/security/2011/dsa-2317
http://www.mandriva.com/security/advisories?name=MDVSA-2011:141
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14012
http://www.redhat.com/support/errata/RHSA-2011-1341.html
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.