|
|
|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/45355
The information has been provided by Gregory Fleischer
|
| |
Vulnerable Systems:
* Mozilla SeaMonkey 2.0.9
* Mozilla SeaMonkey 2.0.8
* Mozilla SeaMonkey 2.0.5
* Mozilla SeaMonkey 2.0.4
* Mozilla SeaMonkey 2.0.3
* Mozilla SeaMonkey 2.0.2
* Mozilla SeaMonkey 2.0.1
* Mozilla SeaMonkey 2.0.9
* Mozilla SeaMonkey 2.0.7
* Mozilla SeaMonkey 2.0.6
* Mozilla SeaMonkey 2.0.5
* Mozilla SeaMonkey 2.0.4
* Mozilla SeaMonkey 2.0.10
* Mozilla SeaMonkey 2.0 Rc2
* Mozilla SeaMonkey 2.0 Rc1
* Mozilla SeaMonkey 2.0 Beta 2
* Mozilla SeaMonkey 2.0 Beta 1
* Mozilla SeaMonkey 2.0 Alpha 3
* Mozilla SeaMonkey 2.0 Alpha 2
* Mozilla SeaMonkey 2.0 Alpha 1
* Mozilla SeaMonkey 2.0
* Mozilla Firefox 3.6.10
* Mozilla Firefox 3.6.9
* Mozilla Firefox 3.6.8
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.4
* Mozilla Firefox 3.6.3
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.6.2
* Mozilla Firefox 3.5.17
* Mozilla Firefox 3.5.14
* Mozilla Firefox 3.5.13
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.10
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.9
* Mozilla Firefox 3.5.8
* Mozilla Firefox 3.5.7
* Mozilla Firefox 3.5.6
* Mozilla Firefox 3.5.5
* Mozilla Firefox 3.5.4
* Mozilla Firefox 3.5.3
* Mozilla Firefox 3.5.2
* Mozilla Firefox 3.5.1
* Mozilla Firefox 3.5
* Mozilla Firefox 3.6.7
* Mozilla Firefox 3.6.6
* Mozilla Firefox 3.6.12
* Mozilla Firefox 3.6.11
* Mozilla Firefox 3.6 Beta 3
* Mozilla Firefox 3.6 Beta 2
* Mozilla Firefox 3.6
* Mozilla Firefox 3.5.15
* Mozilla Firefox 3.5.12
* Mozilla Firefox 3.5.11
Non-Vulnerable Systems:
* Mozilla SeaMonkey 2.0.11
* Mozilla Firefox 3.6.13
* Mozilla Firefox 3.5.16
Attackers can exploit this issue to bypass security restrictions and obtain elevated privileges such as the abilities to read local files, launch processes, and create network connections.
Vendor Status:
Mozilla as issued an update for this vulnerablity
Patch Availability:
http://www.mozilla.org/en-US/products/download.html?product=firefox-12.0&os=win&lang=en-US
CVE Information:
CVE-2010-3775
Disclosure Timeline:
Initial Release Dec 21 2011
|
|
|
|
|