icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Mozilla Firefox 5.0 Multiple Vulnerabilities

High

Synopsis

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Description

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Versions of Firefox 5 are potentially affected by the following security issues :

- A dangling pointer vulnerability exists in an SVG text manipulation routine. (CVE-2011-0084)

- Several memory safety bugs exist in the browser engine that may permit remote code execution. (CVE-2011-2985, CVE-2011-2989, CVE-2011-2991, CVE-2011-2992)

- A cross-origin data theft vulnerability exists when using CANVAS and Windows D2D hardware acceleration. (CVE-2011-2986)

- A heap overflow vulnerability exists in WebGL's ANGLE library. (CVE-2011-2987)

- A buffer overflow vulnerability exists in WebGL when using an overly long shader program. (CVE-2011-2988)

- Two errors exist related to Content Security Policy that can lead to information disclosure. (CVE-2011-2990)

- An unspecified error exists that can allow unsigned JavaScript to call into a signed JAR and inherit the signed JAR's permissions and identity. (CVE-2011-2993)

Solution

Upgrade to Firefox 6.0 or later.