PT-2011-4238 · Mozilla+2 · Thunderbird+4

Ian Graham

·

Publicado

2011-09-27

·

Atualizado

2024-12-12

·

CVE-2011-3000

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.23 Mozilla Firefox versions 4.x through 6 Thunderbird versions prior to 7.0 SeaMonkey versions prior to 2.4
Description The issue arises from improper handling of HTTP responses containing multiple Location, Content-Length, or Content-Disposition headers. This makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Recommendations For Mozilla Firefox versions prior to 3.6.23, update to version 3.6.23 or later. For Mozilla Firefox versions 4.x through 6, update to a version later than 6. For Thunderbird versions prior to 7.0, update to version 7.0 or later. For SeaMonkey versions prior to 2.4, update to version 2.4 or later.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3000
DSA-2312-1
DSA-2313-1
DSA-2317-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2011:1341
RHSA-2011:1342
RHSA-2011_1341
RHSA-2011_1342

Produtos afetados

Firefox
Red Hat
Seamonkey
Suse
Thunderbird