PT-2009-3844 · Mozilla+1 · Firefox+2

Mustlive

·

Publicado

2009-04-21

·

Atualizado

2024-12-12

·

CVE-2009-1312

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.9 SeaMonkey version 1.1.17 Mozilla Firefox version 3.6 a1 pre Mozilla versions 1.7.x and earlier
Description The issue allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to injecting a Refresh header or specifying the content of a Refresh header in HTTP responses, due to the failure to block javascript: URIs in Refresh headers.
Recommendations For Mozilla Firefox versions prior to 3.0.9, update to version 3.0.9 or later. For SeaMonkey version 1.1.17, update to a version later than 1.1.17. For Mozilla Firefox version 3.6 a1 pre, update to a version later than 3.6 a1 pre. For Mozilla versions 1.7.x and earlier, update to a version later than 1.7.x.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1312
DSA-1797-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:0436
RHSA-2009:0437
RHSA-2009_0436
RHSA-2009_0437

Produtos afetados

Firefox
Red Hat
Seamonkey