Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Mozilla Firefox / Thunderbird / SeaMonkey multiple security vulnerabilities

  New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1"

  ZDI-10-176: Mozilla Firefox normalizeDocument Remote Code Execution Vulnerability

  ZDI-10-171: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability

  ZDI-10-172: Mozilla Firefox tree Object Removal Remote Code Execution Vulnerability

From:MOZILLA
Date:10.09.2010
Subject:Mozilla Foundation Security Advisory 2010-63

Mozilla Foundation Security Advisory 2010-63

Title: Information leak via XMLHttpRequest statusText
Impact: Low
Announced: September 7, 2010
Reporter: Matt Haggard, Nicholas Berthaume
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 3.6.9
 Firefox 3.5.12
 Thunderbird 3.1.3
 Thunderbird 3.0.7
 SeaMonkey 2.0.7
Description

Matt Haggard reported that the statusText property of an XMLHttpRequest object is readable by the requestor even when the request is made across origins. This status information reveals the presence of a web server and could be used to gather information about servers on internal private networks.

This issue was also independently reported to Mozilla by Nicholas Berthaume
References

   * https://bugzilla.mozilla.org/show_bug.cgi?id=552090
   * CVE-2010-2764

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru