LWN.net Logo

firefox: multiple vulnerabilities

Package(s):firefox CVE #(s):CVE-2010-1585 CVE-2011-0051 CVE-2011-0053 CVE-2011-0054 CVE-2011-0055 CVE-2011-0056 CVE-2011-0057 CVE-2011-0058 CVE-2011-0059 CVE-2011-0061 CVE-2011-0062
Created:March 2, 2011 Updated:May 2, 2011
Description: From the Red Hat advisory:

A flaw was found in the way Firefox sanitized HTML content in extensions. If an extension loaded or rendered malicious content using the ParanoidFragmentSink class, it could fail to safely display the content, causing Firefox to execute arbitrary JavaScript with the privileges of the user running Firefox. (CVE-2010-1585)

A flaw was found in the way Firefox handled dialog boxes. An attacker could use this flaw to create a malicious web page that would present a blank dialog box that has non-functioning buttons. If a user closes the dialog box window, it could unexpectedly grant the malicious web page elevated privileges. (CVE-2011-0051)

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-0053, CVE-2011-0055, CVE-2011-0058, CVE-2011-0062)

Several flaws were found in the way Firefox handled malformed JavaScript. A website containing malicious JavaScript could cause Firefox to execute that JavaScript with the privileges of the user running Firefox. (CVE-2011-0054, CVE-2011-0056, CVE-2011-0057)

A flaw was found in the way Firefox handled malformed JPEG images. A website containing a malicious JPEG image could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-0061)

A flaw was found in the way Firefox handled plug-ins that perform HTTP requests. If a plug-in performed an HTTP request, and the server sent a 307 redirect response, the plug-in was not notified, and the HTTP request was forwarded. The forwarded request could contain custom headers, which could result in a Cross Site Request Forgery attack. (CVE-2011-0059)

Alerts:
Pardus 2011-56 2011-03-21
Debian DSA-2186-2 2011-03-18
Fedora FEDORA-2011-2797 2011-03-07
Fedora FEDORA-2011-2796 2011-03-07
SUSE SUSE-SA:2011:013 2011-03-15
openSUSE openSUSE-SU-2011:0169-1 2011-03-14
Debian DSA-2187-1 2011-03-09
Debian DSA-2186-1 2011-03-09
Slackware SSA:2011-068-01 2011-03-09
Slackware SSA:2011-068-02 2011-03-09
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Fedora FEDORA-2011-2447 2011-03-02
Ubuntu USN-1049-2 2011-03-07
Mandriva MDVSA-2011:042 2011-03-07
Mandriva MDVSA-2011:041 2011-03-03
Debian DSA-2180-1 2011-03-03
Ubuntu USN-1050-1 2011-03-03
Ubuntu USN-1049-1 2011-03-03
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
Fedora FEDORA-2011-2444 2011-03-02
CentOS CESA-2011:0310 2011-03-02
CentOS CESA-2011:0312 2011-03-02
CentOS CESA-2011:0313 2011-03-02
Slackware SSA:2011-060-01 2011-03-02
Red Hat RHSA-2011:0312-01 2011-03-01
Red Hat RHSA-2011:0311-01 2011-03-01
Red Hat RHSA-2011:0313-01 2011-03-01
Red Hat RHSA-2011:0310-01 2011-03-01
Ubuntu USN-1123-1 2011-04-30
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds