Mozilla Firefox / Thunderbird Multiple Vulnerabilities
Last Update Date:
15 Jan 2015 11:53
Release Date:
15 Jan 2015
3664
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, conduct cross-site request forgery attacks, and obtain potentially sensitive information.
- A remote user can create specially crafted HTML that, when loaded by the target user, will execute arbitrary code on the target system.
- The navigator.sendBeacon() function does not honour the cross-origin resource sharing (CORS) specification. A remote user can exploit this to conduct cross-site request forgery attacks.
- A remote Web Proxy can return an HTTP 407 Proxy Authentication response with a specially crafted Set-Cookie header value to inject cookies and conduct session-fixation attacks.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Information Disclosure
System / Technologies affected
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (Firefox 35.0, Thunderbird 34.1).
Vulnerability Identifier
- CVE-2014-8634
- CVE-2014-8635
- CVE-2014-8636
- CVE-2014-8637
- CVE-2014-8638
- CVE-2014-8639
- CVE-2014-8640
- CVE-2014-8641
- CVE-2014-8642
- CVE-2014-8643
Source
Related Link
Share with