Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure
FLEA-2007-0001-1: firefox
 

Index | Next | Previous | View Flat


foresight-security-noreply at foresightlinux

Mar 21, 2007, 9:42 PM


Views: 206
Permalink
FLEA-2007-0001-1: firefox

Foresight Linux Essential Advisory: 2007-0001-1
Published: 2007-03-22

Rating: Minor

Updated Versions:
firefox=/foresight.rpath.org[at]fl:1-devel//1/2.0.0.3-1-1
group-dist=/foresight.rpath.org[at]fl:1-devel//1/1.1-0.8-2

References:
http://www.mozilla.org/security/announce/2007/mfsa2007-11.html

Description:
Previous versions of the Firefox package were vulnerable to an
information disclosure issue. Firefox's handling of PASV FTP connections
could allow a specially crafted server to perform rudimentary port
scanning on the client machine, giving the FTP server information about
the client's system. In and of itself, this is not going to cause a
remote code exploit, but could aid a malicious individual in other attacks.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Subject User Time
FLEA-2007-0001-1: firefox foresight-security-noreply at foresightlinux Mar 21, 2007, 9:42 PM

  Index | Next | Previous | View Flat
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.