漏洞信息详情
Firefox多个Mozilla/Firefox/Thunderbird漏洞
漏洞简介
不安全的页面从受信站点加载二进制文件时,Firefox 1.0之前版本和Mozilla 1.7.5之前版本会显示SSL锁定图标,从而有利于网络钓鱼攻击。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: RedHat Fedora Core2 Fedora devhelp-0.9.1-0.2.5.i386.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora devhelp-0.9.1-0.2.5.x86_64.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora devhelp-debuginfo-0.9.1-0.2.5.i386.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora devhelp-debuginfo-0.9.1-0.2.5.x86_64.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora epiphany-1.2.10-0.2.1.i386.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora epiphany-1.2.10-0.2.1.x86_64.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora epiphany-debuginfo-1.2.10-0.2.1.i386.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Fedora epiphany-debuginfo-1.2.10-0.2.1.x86_64.rpm RedHat Fedora Core 2 http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ Mozilla Firefox 0.10 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/ Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 1.0 http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 1.0 http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US Mozilla Firefox 0.8 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/ Mozilla Thunderbird 0.8 Mozilla Thunderbird 1.0 http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US Mozilla Firefox 0.9 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/ Mozilla Thunderbird 0.9 Mozilla Thunderbird 1.0 http://download.mozilla.org/?product=thunderbird&os=win&lang=en-US Mozilla Firefox 0.9.1 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/ Mozilla Firefox 0.9.2 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/ Mozilla Firefox 0.9.3 Mozilla Firefox 1.0 http://www.mozilla.org/products/firefox/
参考网址
来源: bugzilla.mozilla.org 链接:https://bugzilla.mozilla.org/show_bug.cgi?id=257308 来源: XF 名称: mozilla-ssl-spoofing(19166) 链接:http://xforce.iss.net/xforce/xfdb/19166 来源: REDHAT 名称: RHSA-2005:335 链接:http://www.redhat.com/support/errata/RHSA-2005-335.html 来源: www.mozilla.org 链接:http://www.mozilla.org/security/announce/mfsa2005-03.html 来源: BID 名称: 12407 链接:http://www.securityfocus.com/bid/12407 来源: REDHAT 名称: RHSA-2005:384 链接:http://www.redhat.com/support/errata/RHSA-2005-384.html 来源: US Government Resource: oval:org.mitre.oval:def:100055 名称: oval:org.mitre.oval:def:100055 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055
受影响实体
- Mozilla Mozilla:1.5:Alpha<!--2000-1-1-->
- Mozilla Mozilla:1.5:Rc1<!--2000-1-1-->
- Mozilla Mozilla:1.5:Rc2<!--2000-1-1-->
- Mozilla Mozilla:1.5.1<!--2000-1-1-->
- Mozilla Mozilla:1.6<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...