PT-2011-4238 · Mozilla+2 · Thunderbird+4

Ian Graham

·

Published

2011-09-27

·

Updated

2024-12-12

·

CVE-2011-3000

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.23 Mozilla Firefox versions 4.x through 6 Thunderbird versions prior to 7.0 SeaMonkey versions prior to 2.4
Description The issue arises from improper handling of HTTP responses containing multiple Location, Content-Length, or Content-Disposition headers. This makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Recommendations For Mozilla Firefox versions prior to 3.6.23, update to version 3.6.23 or later. For Mozilla Firefox versions 4.x through 6, update to a version later than 6. For Thunderbird versions prior to 7.0, update to version 7.0 or later. For SeaMonkey versions prior to 2.4, update to version 2.4 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3000
DSA-2312-1
DSA-2313-1
DSA-2317-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2011:1341
RHSA-2011:1342
RHSA-2011_1341
RHSA-2011_1342

Affected Products

Firefox
Red Hat
Seamonkey
Suse
Thunderbird