Firefox < 8.0 Multiple Vulnerabilities (Mac OS X)

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.

Synopsis :

The remote Mac OS X host contains a web browser that is potentially
affected by multiple vulnerabilities.

Description :

The installed version of Firefox is earlier than 8.0 and thus, is
potentially affected by the following security issues :

- Certain invalid sequences are not handled properly in
'Shift-JIS' encoding, which can allow cross-site
scripting attacks. (CVE-2011-3648)

- Profiling JavaScript files with many functions can cause
the application to crash. It may be possible to trigger
this behavior even when the debugging APIs are not being
used. (CVE-2011-3650)

- Multiple memory safety issues exist. (CVE-2011-3651)

- An unchecked memory allocation failure can cause the
application to crash. (CVE-2011-3652)

- An issue with WebGL graphics and GPU drivers can allow
cross-origin image theft. (CVE-2011-3653)

- An error exists related to SVG 'mpath' linking to a
non-SVG element, which can result in potentially
exploitable application crashes. (CVE-2011-3654)

- An error in internal privilege checking can allow
web content to obtain elevated privileges.

See also :

Solution :

Upgrade to Firefox 8.0 or later.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : true

Family: MacOS X Local Security Checks

Nessus Plugin ID: 56756 ()

Bugtraq ID: 50592

CVE ID: CVE-2011-3648

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial