漏洞信息详情
Mozilla Firefox 输入验证错误漏洞
漏洞简介
Mozilla Firefox是美国Mozilla基金会的一款开源Web浏览器。
Mozilla Firefox before 2.0.0.8之前版本中存在输入验证错误漏洞。攻击者可利用该漏洞加载错误的协议处理程序。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://www.mozilla.org/projects/seamonkey/
http://www.mozilla.com/en-US/firefox/
http://www.mozilla.com/en-US/thunderbird/
RedHat已经为此发布了安全公告(RHSA-2007:0979-01,RHSA-2007:0981-01,RHSA-2007:0980-01)以及相应补丁:
RHSA-2007:0979-01:Critical: firefox security update
链接:
https://www.redhat.com/support/errata/RHSA-2007-0979.html
RHSA-2007:0981-01:Moderate: thunderbird security update
链接:
https://www.redhat.com/support/errata/RHSA-2007-0981.html
RHSA-2007:0980-01:Critical: seamonkey security update
链接:
https://www.redhat.com/support/errata/RHSA-2007-0980.html
参考网址
来源:MISC
链接:http://xs-sniper.com/blog/2007/09/01/firefox-file-handling-woes/
来源:MANDRIVA
链接:http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202
来源:HP
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
来源:BID
链接:https://www.securityfocus.com/bid/25543
来源:SECUNIA
链接:http://secunia.com/advisories/27315
来源:SECUNIA
链接:http://secunia.com/advisories/27414
来源:SECUNIA
链接:http://secunia.com/advisories/27744
来源:SECUNIA
链接:http://secunia.com/advisories/27360
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2007/3544
来源:CONFIRM
链接:http://www.mozilla.org/security/announce/2007/mfsa2007-36.html
来源:HP
链接:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579
来源:SECUNIA
链接:http://secunia.com/advisories/27311
来源:SECUNIA
链接:http://secunia.com/advisories/28398
来源:SLACKWARE
链接:http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.471007
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/0083
来源:SECUNIA
链接:http://secunia.com/advisories/28363
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/0082
受影响实体
- Mozilla Firefox:2.0.0.8<!--2000-1-1-->
- Mozilla Seamonkey:1.1.5<!--2000-1-1-->
- Mozilla Thunderbird:2.0.0.8<!--2000-1-1-->
补丁
- Mozilla Firefox 输入验证错误漏洞的修复措施<!--2007-4-25-->
还没有评论,来说两句吧...