Описание
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | seamonkey | Will not fix | ||
Red Hat Enterprise Linux 4 | firefox | Fixed | RHSA-2010:0500 | 22.06.2010 |
Red Hat Enterprise Linux 5 | devhelp | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | esc | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | firefox | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | gnome-python2-extras | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | totem | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | xulrunner | Fixed | RHSA-2010:0501 | 22.06.2010 |
Red Hat Enterprise Linux 5 | yelp | Fixed | RHSA-2010:0501 | 22.06.2010 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.6 Low
CVSS2
Связанные уязвимости
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
The Math.random function in the JavaScript implementation in Mozilla F ...
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
ELSA-2010-0501: firefox security, bug fix, and enhancement update (CRITICAL)
EPSS
3.6 Low
CVSS2