Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

FLEA-2007-0001-1: firefox

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


foresight-security-noreply at foresightlinux

Mar 21, 2007, 9:42 PM

Post #1 of 1 (205 views)
Permalink
FLEA-2007-0001-1: firefox

Foresight Linux Essential Advisory: 2007-0001-1
Published: 2007-03-22

Rating: Minor

Updated Versions:
firefox=/foresight.rpath.org[at]fl:1-devel//1/2.0.0.3-1-1
group-dist=/foresight.rpath.org[at]fl:1-devel//1/1.1-0.8-2

References:
http://www.mozilla.org/security/announce/2007/mfsa2007-11.html

Description:
Previous versions of the Firefox package were vulnerable to an
information disclosure issue. Firefox's handling of PASV FTP connections
could allow a specially crafted server to perform rudimentary port
scanning on the client machine, giving the FTP server information about
the client's system. In and of itself, this is not going to cause a
remote code exploit, but could aid a malicious individual in other attacks.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.