Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Firefox Security Advisory (MFSA2015-66) - Linux
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is missing a security update for Mozilla Firefox.
Insight
Insight
Vulnerabilities found through code inspection Security researcher Ronald Crane reported seven vulnerabilities affecting released code that he found through code inspection. These included three uses of uninitialized memory, one poor validation leading to an exploitable crash, one read of unowned memory in zip files, and two buffer overflows. These do not all have clear mechanisms to be exploited through web content but are vulnerable if a mechanism can be found to trigger them.
Affected Software
Affected Software
Firefox version(s) below 39.
Detection Method
Detection Method
Checks if a vulnerable package version is present on the target host.
Solution
Solution
The vendor has released an update. Please see the reference(s) for more information.
Common Vulnerabilities and Exposures (CVE)
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2015-66/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1166082
- https://bugzilla.mozilla.org/show_bug.cgi?id=1166900
- https://bugzilla.mozilla.org/show_bug.cgi?id=1167332
- https://bugzilla.mozilla.org/show_bug.cgi?id=1167356
- https://bugzilla.mozilla.org/show_bug.cgi?id=1167888
- https://bugzilla.mozilla.org/show_bug.cgi?id=1168207
- https://bugzilla.mozilla.org/show_bug.cgi?id=1170809