Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-2372

Опубликовано: 29 сент. 2011
Источник: debian

Описание

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icedovefixed3.1.15-1package
icedoveend-of-lifelennypackage
xulrunnerremovedpackage
iceweaselfixed7.0-1package
iceweaselnot-affectedlennypackage
iceapefixed2.0.14-8package
iceapenot-affectedlennypackage

Примечания

  • xulrunner in wheezy is not covered by security support

Связанные уязвимости

ubuntu
больше 14 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

redhat
больше 14 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

nvd
больше 14 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

github
почти 4 года назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

oracle-oval
больше 14 лет назад

ELSA-2011-1342: thunderbird security update (CRITICAL)