FreeBSD : mozilla -- multiple vulnerabilities (49e8f2ee-8147-11de-a994-0030843d3802)

High Nessus Plugin ID 40485


The remote FreeBSD host is missing one or more security-related updates.


Mozilla Project reports :

MFSA 2009-38: Data corruption with SOCKS5 reply containing DNS name longer than 15 characters

MFSA 2009-42: Compromise of SSL-protected communication

MFSA 2009-43: Heap overflow in certificate regexp parsing

MFSA 2009-44: Location bar and SSL indicator spoofing via on invalid URL

MFSA 2009-45: Crashes with evidence of memory corruption (rv:

MFSA 2009-46: Chrome privilege escalation due to incorrectly cached wrapper


Update the affected packages.

See Also

Plugin Details

Severity: High

ID: 40485

File Name: freebsd_pkg_49e8f2ee814711dea9940030843d3802.nasl

Version: $Revision: 1.17 $

Type: local

Published: 2009/08/05

Modified: 2016/12/08

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:firefox, p-cpe:/a:freebsd:freebsd:linux-firefox, p-cpe:/a:freebsd:freebsd:linux-firefox-devel, p-cpe:/a:freebsd:freebsd:linux-seamonkey, p-cpe:/a:freebsd:freebsd:linux-seamonkey-devel, p-cpe:/a:freebsd:freebsd:linux-thunderbird, p-cpe:/a:freebsd:freebsd:seamonkey, p-cpe:/a:freebsd:freebsd:thunderbird, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2009/08/04

Vulnerability Publication Date: 2009/08/03

Reference Information

CVE: CVE-2009-2404, CVE-2009-2408, CVE-2009-2454, CVE-2009-2470

CWE: 20, 79, 119, 310