|
|
|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/45314
The information has been provided by Michal Zalewski
|
| |
Vulnerable Systems:
* Mozilla Firefox 3.6.10
* Mozilla Firefox 3.6.9
* Mozilla Firefox 3.6.8
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.4
* Mozilla Firefox 3.6.3
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.5.17
* Mozilla Firefox 3.5.14
* Mozilla Firefox 3.5.13
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.8
* Mozilla Firefox 3.5.7
* Mozilla Firefox 3.5.6
* Mozilla Firefox 3.5.5
* Mozilla Firefox 3.5.4
* Mozilla Firefox 3.5.3
* Mozilla Firefox 3.5.2
* Mozilla Firefox 3.5.1
* Mozilla Firefox 3.5
* Mozilla Firefox 3.6.7
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.12
* Mozilla Firefox 3.6.11
* Mozilla Firefox 3.5.15
* Mozilla Firefox 3.5.12
* Mozilla Firefox 3.5.11
Non-Vulnerable Systems:
* Mozilla Firefox 3.6.13
Attackers can exploit this issue to bypass the same-origin policy. Successful exploits may allow attacker to mislead unsuspecting victims, steal sensitive information, or launch other attacks.
Vendor Status:
Mozilla as issued an update for this vulnerablity
Patch Availability:
http://www.mozilla.org/en-US/products/download.html?product=firefox-12.0&os=win&lang=en-US
CVE Information:
CVE-2010-3774
Disclosure Timeline:
Initial Release Dec 21 2011
|
|
|
|
|