PT-2012-1734 · Mozilla+3 · Firefox+5
Publicado
2012-01-31
·
Atualizado
2017-12-29
·
CVE-2011-3670
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0
Thunderbird versions prior to 3.1.18 and 5.0 through 6.0
SeaMonkey versions prior to 2.4
Description
The issue allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages, due to the improper enforcement of the IPv6 literal address syntax.
Recommendations
For Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0, update to a version that properly enforces the IPv6 literal address syntax.
For Thunderbird versions prior to 3.1.18 and 5.0 through 6.0, update to a version that properly enforces the IPv6 literal address syntax.
For SeaMonkey versions prior to 2.4, update to a version that properly enforces the IPv6 literal address syntax.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Firefox
Red Hat
Seamonkey
Suse
Thunderbird