FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-3670

This CVE name corresponds to:

Entered Topic
2012-02-01 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-3670
Phase Assigned(20110923)

Description

Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2012/mfsa2012-02.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=504014
DEBIAN DSA-2400
MANDRIVA MDVSA-2012:013
SUSE SUSE-SU-2012:0198
SUSE SUSE-SU-2012:0221
SUSE openSUSE-SU-2012:0234
OVAL oval:org.mitre.oval:def:14814