RHEL 4 : firefox (RHSA-2008:0549)

critical Nessus Plugin ID 33424

Synopsis

The remote Red Hat host is missing a security update.

Description

An updated firefox package that fixes several security issues is now available for Red Hat Enterprise Linux 4.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

Mozilla Firefox is an open source Web browser.

Multiple flaws were found in the processing of malformed JavaScript content. A web page containing such malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A web page containing specially crafted content could potentially trick a Firefox user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Firefox. A web page containing malicious content could cause Firefox to reveal the contents of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by Firefox. A malicious extension could read uninitialized memory, possibly leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Firefox escaped a listing of local file names. If a user could be tricked into listing a local directory containing malicious file names, arbitrary JavaScript could be run with the permissions of the user running Firefox. (CVE-2008-2808)

A flaw was found in the way Firefox displayed information about self-signed certificates. It was possible for a self-signed certificate to contain multiple alternate name entries, which were not all displayed to the user, allowing them to mistakenly extend trust to an unknown site. (CVE-2008-2809)

All Mozilla Firefox users should upgrade to this updated package, which contains backported patches that correct these issues.

Solution

Update the affected firefox package.

See Also

https://access.redhat.com/security/cve/cve-2008-2798

https://access.redhat.com/security/cve/cve-2008-2799

https://access.redhat.com/security/cve/cve-2008-2800

https://access.redhat.com/security/cve/cve-2008-2801

https://access.redhat.com/security/cve/cve-2008-2802

https://access.redhat.com/security/cve/cve-2008-2803

https://access.redhat.com/security/cve/cve-2008-2805

https://access.redhat.com/security/cve/cve-2008-2807

https://access.redhat.com/security/cve/cve-2008-2808

https://access.redhat.com/security/cve/cve-2008-2809

https://access.redhat.com/security/cve/cve-2008-2810

https://access.redhat.com/security/cve/cve-2008-2811

https://access.redhat.com/errata/RHSA-2008:0549

Plugin Details

Severity: Critical

ID: 33424

File Name: redhat-RHSA-2008-0549.nasl

Version: 1.27

Type: local

Agent: unix

Published: 7/8/2008

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:firefox, cpe:/o:redhat:enterprise_linux:4, cpe:/o:redhat:enterprise_linux:4.6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 7/2/2008

Vulnerability Publication Date: 7/7/2008

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2810, CVE-2008-2811

BID: 30038

CWE: 20, 200, 264, 287, 399, 79

RHSA: 2008:0549