Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64

This script is Copyright (C) 2015 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing one or more security

Description :

A flaw was discovered in Mozilla Firefox that could be used to violate
the same-origin policy and inject web script into a non-privileged
part of the built-in PDF file viewer (PDF.js). An attacker could
create a malicious web page that, when viewed by a victim, could steal
arbitrary files (including private SSH keys, the /etc/passwd file, and
other potentially sensitive files) from the system running Firefox.

After installing the update, Firefox must be restarted for the changes
to take effect.

See also :

Solution :

Update the affected firefox and / or firefox-debuginfo packages.

Risk factor :

Medium / CVSS Base Score : 4.3
Public Exploit Available : true

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 85296 ()

Bugtraq ID:

CVE ID: CVE-2015-4495

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now