PT-2011-3809 · Mozilla · Firefox

Moz_Bug_R_A4

·

Publicado

2011-06-21

·

Atualizado

2024-12-12

·

CVE-2011-2370

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 5.0
Description The issue is related to the xpinstall functionality in Mozilla Firefox, where the whitelist is not properly enforced. This allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.
Recommendations For versions prior to 5.0, update to version 5.0 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2370
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1

Produtos afetados

Firefox