PT-2012-1734 · Mozilla+3 · Firefox+5

Published

2012-01-31

·

Updated

2017-12-29

·

CVE-2011-3670

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0 Thunderbird versions prior to 3.1.18 and 5.0 through 6.0 SeaMonkey versions prior to 2.4
Description The issue allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages, due to the improper enforcement of the IPv6 literal address syntax.
Recommendations For Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0, update to a version that properly enforces the IPv6 literal address syntax. For Thunderbird versions prior to 3.1.18 and 5.0 through 6.0, update to a version that properly enforces the IPv6 literal address syntax. For SeaMonkey versions prior to 2.4, update to a version that properly enforces the IPv6 literal address syntax.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0079
CESA-2012_0080
CVE-2011-3670
DSA-2400-1
DSA-2402-1
DSA-2406-1
RHSA-2012:0079
RHSA-2012:0080
RHSA-2012:0084
RHSA-2012:0085
RHSA-2012_0079
RHSA-2012_0080
RHSA-2012_0084
RHSA-2012_0085

Affected Products

Centos
Firefox
Red Hat
Seamonkey
Suse
Thunderbird