Firefox 3.6.7 Remote Code Execution

This script is Copyright (C) 2010-2017 Tenable Network Security, Inc.


Synopsis :

The remote Windows host contains a web browser that may allow
execution of remote code.

Description :

The installed version of Firefox is 3.6.7. This version is
potentially affected by a memory corruption vulnerability that could
lead to arbitrary code execution. (MFSA 2010-48)

See also :

https://www.mozilla.org/en-US/security/advisories/mfsa2010-48/
http://www.nessus.org/u?bdee8b29

Solution :

Upgrade to Firefox 3.6.8 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.3
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 47829 ()

Bugtraq ID: 41933

CVE ID: CVE-2010-2755

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now