PT-2012-1734 · Mozilla+3 · Firefox+5
Published
2012-01-31
·
Updated
2017-12-29
·
CVE-2011-3670
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0
Thunderbird versions prior to 3.1.18 and 5.0 through 6.0
SeaMonkey versions prior to 2.4
Description
The issue allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages, due to the improper enforcement of the IPv6 literal address syntax.
Recommendations
For Mozilla Firefox versions prior to 3.6.26 and 4.x through 6.0, update to a version that properly enforces the IPv6 literal address syntax.
For Thunderbird versions prior to 3.1.18 and 5.0 through 6.0, update to a version that properly enforces the IPv6 literal address syntax.
For SeaMonkey versions prior to 2.4, update to a version that properly enforces the IPv6 literal address syntax.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Firefox
Red Hat
Seamonkey
Suse
Thunderbird