Mozilla Products Mulitple Vulnerabilities
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Mozilla Firefox, Thunderbird and SeaMonkey, which could be exploited by attackers to manipulate or disclose certain data, bypass security restrictions or compromise a vulnerable system. These issues are caused by memory corruptions, dangling pointers, input validation errors, and information disclosure related to the browser engine, mChannel, mObserverList, nsTreeRange, form autocomplete controls, Java Embedding Plugin (JEP), "resource:" protocol, WebGLES, and XSLT.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Mozilla Firefox versions prior to 4.0.1
- Mozilla Firefox versions prior to 3.6.17
- Mozilla Firefox versions prior to 3.5.19
- Mozilla Thunderbird versions prior to 3.1.10
- Mozilla SeaMonkey versions prior to 2.0.14
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Mozilla Firefox version 4.0.1, 3.6.17 or 3.5.19 :
http://www.mozilla.com/firefox/ - Upgrade to Mozilla Thunderbird version 3.1.10 :
http://www.mozilla.com/thunderbird/ - Upgrade to Mozilla SeaMonkey version 2.0.14 :
http://www.mozilla.com/seamonkey/
Vulnerability Identifier
- CVE-2011-0065
- CVE-2011-0066
- CVE-2011-0067
- CVE-2011-0068
- CVE-2011-0069
- CVE-2011-0070
- CVE-2011-0071
- CVE-2011-0072
- CVE-2011-0073
- CVE-2011-0074
- CVE-2011-0075
- CVE-2011-0076
- CVE-2011-0077
- CVE-2011-0078
- CVE-2011-0079
- CVE-2011-0080
- CVE-2011-0081
- CVE-2011-1202
Source
Related Link
- http://secunia.com/advisories/44407/
- http://secunia.com/advisories/44406/
- http://secunia.com/advisories/44357/
- http://www.vupen.com/english/advisories/2011/1127
- http://www.mozilla.org/security/announce/2011/mfsa2011-12.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-13.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-14.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-15.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-16.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-17.html
- http://www.mozilla.org/security/announce/2011/mfsa2011-18.html
Share with