Full Disclosure mailing list archives
FLEA-2007-0001-1: firefox
From: Foresight Linux Essential Announcement Service <foresight-security-noreply () foresightlinux org>
Date: Thu, 22 Mar 2007 00:42:32 -0400
Foresight Linux Essential Advisory: 2007-0001-1 Published: 2007-03-22 Rating: Minor Updated Versions: firefox=/foresight.rpath.org@fl:1-devel//1/2.0.0.3-1-1 group-dist=/foresight.rpath.org@fl:1-devel//1/1.1-0.8-2 References: http://www.mozilla.org/security/announce/2007/mfsa2007-11.html Description: Previous versions of the Firefox package were vulnerable to an information disclosure issue. Firefox's handling of PASV FTP connections could allow a specially crafted server to perform rudimentary port scanning on the client machine, giving the FTP server information about the client's system. In and of itself, this is not going to cause a remote code exploit, but could aid a malicious individual in other attacks. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- FLSA - foresight linux security announcements Jonathan Smith (Mar 08)
- Message not available
- FLEA-2007-0001-1: firefox Foresight Linux Essential Announcement Service (Mar 21)
- Message not available
- Message not available
- FLEA-2007-0002-1: inkscape Foresight Linux Essential Announcement Service (Mar 24)
- Message not available
- FLEA-2007-0003-1: cups Foresight Linux Essential Announcement Service (Mar 25)
- Message not available
- FLEA-2007-0004-1: openoffice.org Foresight Linux Essential Announcement Service (Mar 29)
- Message not available
- FLEA-2007-0005-1: slocate Foresight Linux Essential Announcement Service (Mar 29)