Lucene search

K
seebugRootSSV:20801
HistoryAug 01, 2011 - 12:00 a.m.

Mozilla Firefox and SeaMonkey Java LiveConnect Script Security Bypass Vulnerability

2011-08-0100:00:00
Root
www.seebug.org
23

EPSS

0.023

Percentile

89.8%

CVE:CVE-2010-3775
Bugtraq ID:45355

Mozilla Firefox and SeaMonkey are prone to a security-bypass vulnerability.

Attackers can exploit this issue to bypass security restrictions and obtain elevated privileges such as the abilities to read local files, launch processes, and create network connections.

This issue is fixed in:

Firefox 3.6.13
Firefox 3.5.16
SeaMonkey 2.0.11

NOTE: This issue was previously covered in BID 45322 (Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2010-74 -82, 84 Multiple Vulnerabilities), but has been assigned its own record to better document it.

Ubuntu Ubuntu Linux 9.10 sparc
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 9.10 lpia
Ubuntu Ubuntu Linux 9.10 i386
Ubuntu Ubuntu Linux 9.10 ARM
Ubuntu Ubuntu Linux 9.10 amd64
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 8.04 LTS i386
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 10.10 powerpc
Ubuntu Ubuntu Linux 10.10 i386
Ubuntu Ubuntu Linux 10.10 ARM
Ubuntu Ubuntu Linux 10.10 amd64
Ubuntu Ubuntu Linux 10.04 sparc
Ubuntu Ubuntu Linux 10.04 powerpc
Ubuntu Ubuntu Linux 10.04 i386
Ubuntu Ubuntu Linux 10.04 ARM
Ubuntu Ubuntu Linux 10.04 amd64
SuSE SUSE Linux Enterprise Server 11 SP1
SuSE SUSE Linux Enterprise Server 10 SP3
SuSE SUSE Linux Enterprise SDK 11 SP1
SuSE SUSE Linux Enterprise SDK 10 SP3
SuSE SUSE Linux Enterprise Desktop 11 SP1

  • Linux kernel 2.6.5
    SuSE SUSE Linux Enterprise Desktop 10 SP3
    SuSE openSUSE 11.3
    Slackware Linux x86_64 -current
    Slackware Linux 13.1 x86_64
    Slackware Linux 13.1
    Slackware Linux 13.0 x86_64
    Slackware Linux 13.0
    Slackware Linux -current
    S.u.S.E. openSUSE 11.2
    S.u.S.E. openSUSE 11.1
    RedHat Enterprise Linux WS 4
    RedHat Enterprise Linux ES 4
    RedHat Enterprise Linux Desktop Workstation 5 client
    RedHat Enterprise Linux AS 4
    RedHat Enterprise Linux Desktop version 4
    RedHat Enterprise Linux 5 server
    Red Hat Fedora 14
    Red Hat Fedora 13
    Red Hat Enterprise Linux Workstation Optional 6
    Red Hat Enterprise Linux Workstation 6
    Red Hat Enterprise Linux Server Optional 6
    Red Hat Enterprise Linux Server 6
    Red Hat Enterprise Linux HPC Node Optional 6
    Red Hat Enterprise Linux Desktop Optional 6
    Red Hat Enterprise Linux Desktop 6
    Red Hat Enterprise Linux Desktop 5 client
    Mozilla SeaMonkey 2.0.9
    Mozilla SeaMonkey 2.0.8
    Mozilla SeaMonkey 2.0.5
    Mozilla SeaMonkey 2.0.4
    Mozilla SeaMonkey 2.0.3
    Mozilla SeaMonkey 2.0.2
    Mozilla SeaMonkey 2.0.1
    Mozilla SeaMonkey 2.0.9
    Mozilla SeaMonkey 2.0.7
    Mozilla SeaMonkey 2.0.6
    Mozilla SeaMonkey 2.0.5
    Mozilla SeaMonkey 2.0.4
    Mozilla SeaMonkey 2.0.10
    Mozilla SeaMonkey 2.0 Rc2
    Mozilla SeaMonkey 2.0 Rc1
    Mozilla SeaMonkey 2.0 Beta 2
    Mozilla SeaMonkey 2.0 Beta 1
    Mozilla SeaMonkey 2.0 Alpha 3
    Mozilla SeaMonkey 2.0 Alpha 2
    Mozilla SeaMonkey 2.0 Alpha 1
    Mozilla SeaMonkey 2.0
    Mozilla Firefox 3.6.10
    Mozilla Firefox 3.6.9
    Mozilla Firefox 3.6.8
    Mozilla Firefox 3.6.6
    Mozilla Firefox 3.6.4
    Mozilla Firefox 3.6.3
    Mozilla Firefox 3.6.2
    Mozilla Firefox 3.6.2
    Mozilla Firefox 3.5.17
    Mozilla Firefox 3.5.14
    Mozilla Firefox 3.5.13
    Mozilla Firefox 3.5.10
    Mozilla Firefox 3.5.10
    Mozilla Firefox 3.5.9
    Mozilla Firefox 3.5.9
    Mozilla Firefox 3.5.8
    Mozilla Firefox 3.5.7
    Mozilla Firefox 3.5.6
    Mozilla Firefox 3.5.5
    Mozilla Firefox 3.5.4
    Mozilla Firefox 3.5.3
    Mozilla Firefox 3.5.2
    Mozilla Firefox 3.5.1
    Mozilla Firefox 3.5
    Mozilla Firefox 3.6.7
    Mozilla Firefox 3.6.6
    Mozilla Firefox 3.6.12
    Mozilla Firefox 3.6.11
    Mozilla Firefox 3.6 Beta 3
    Mozilla Firefox 3.6 Beta 2
    Mozilla Firefox 3.6
    Mozilla Firefox 3.5.15
    Mozilla Firefox 3.5.12
    Mozilla Firefox 3.5.11
    MandrakeSoft Linux Mandrake 2010.1 x86_64
    MandrakeSoft Linux Mandrake 2010.1
    MandrakeSoft Linux Mandrake 2010.0 x86_64
    MandrakeSoft Linux Mandrake 2010.0
    MandrakeSoft Linux Mandrake 2009.0 x86_64
    MandrakeSoft Linux Mandrake 2009.0
    MandrakeSoft Enterprise Server 5 x86_64
    MandrakeSoft Enterprise Server 5
    Avaya Messaging Storage Server MSS 5.1
    Avaya Messaging Storage Server MSS 4.1
    Avaya Messaging Storage Server 5.2.8
    Avaya Messaging Storage Server 5.2.2
    Avaya Messaging Storage Server 5.2 SP3
    Avaya Messaging Storage Server 5.2 SP2
    Avaya Messaging Storage Server 5.2 SP1
    Avaya Messaging Storage Server 5.2
    Avaya Messaging Storage Server 5.1 SP2
    Avaya Messaging Storage Server 5.1 SP1
    Avaya Messaging Storage Server 5.1
    Avaya Messaging Storage Server 5.0
    Avaya Messaging Storage Server 4.0
    Avaya Message Networking 5.2.1
    Avaya Message Networking MN 3.1
    Avaya Message Networking 5.2.2
    Avaya Message Networking 5.2 SP1
    Avaya Message Networking 5.2
    Avaya Message Networking 3.1
    Avaya IQ 4.1
    Avaya IQ 5.1
    Avaya IQ 5
    Avaya IQ 4.2
    Avaya IQ 4.0
    Avaya Intuity AUDIX LX 2.0 SP2
    Avaya Intuity AUDIX LX 2.0 SP1
    Avaya Intuity AUDIX LX 2.0
    Avaya Communication Server 1000M Signaling Server 7.5
    Avaya Communication Server 1000M Signaling Server 7.0
    Avaya Communication Server 1000M 7.5
    Avaya Communication Server 1000M 7.0
    Avaya Communication Server 1000E Signaling Server 7.5
    Avaya Communication Server 1000E Signaling Server 7.0
    Avaya Communication Server 1000E 7.5
    Avaya Communication Server 1000E 7.0
    Avaya Aura System Manager 6.1.1
    Avaya Aura System Manager 6.1
    Avaya Aura System Manager 6.0 SP1
    Avaya Aura System Manager 6.0
    Avaya Aura System Manager 5.2
    Avaya Aura Session Manager 6.1.2
    Avaya Aura Session Manager 6.1.1
    Avaya Aura Session Manager 6.1
    Avaya Aura Session Manager 6.0 SP1
    Avaya Aura Session Manager 6.0
    Avaya Aura Session Manager 5.2 SP2
    Avaya Aura Session Manager 5.2 SP1
    Avaya Aura Session Manager 5.2
    Avaya Aura Session Manager 1.1
    Avaya Aura Presence Services 6.1
    Avaya Aura Presence Services 6.0
    http://security.ubuntu.com/ubuntu/pool/universe/f/firefox-3.5/abrowser -3.0-branding_3.6.13+build3+nobinonly-0ubuntu0.9.10.1_all.deb
    http://www.securityfocus.com/bid/45355/solution