Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-1562
StatusCandidate
DescriptionThe FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
SeverityMedium
CVSS score5,6
CVSS vector(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (21.03.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1562
ReferencesBID : 23082
 BUGTRAQ : 20070322 FLEA-2007-0001-1: firefox
 BUGTRAQ : 20070531 FLEA-2007-0023-1: firefox
 CONFIRM : http://www.mozilla.org/security/announce/2007/mfsa...
 CONFIRM : https://issues.rpath.com/browse/RPL-1157
 CONFIRM : https://issues.rpath.com/browse/RPL-1424
 FRSIRT : ADV-2007-1034
 MISC : http://bindshell.net/papers/ftppasv/ftp-client-pas...
 MISC : https://bugzilla.mozilla.org/show_bug.cgi?id=370559
 REDHAT : RHSA-2007:0400
 REDHAT : RHSA-2007:0402
 SECTRACK : 1017800
 SECUNIA : 25476
 SECUNIA : 25490
 SUSE : SUSE-SA:2007:036
 UBUNTU : USN-443-1
 XF : firefox-nsftpstate-information-disclosure(33119)
SecurityVulns:Multiple FTP clients FTP bounce attack
 Mozilla Firefox / Thunderbird / SeaMonkey multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru