Oval Definition:oval:org.mitre.oval:def:23411
Revision Date:2014-05-26Version:65
Title:ELSA-2011:0885: firefox security and bug fix update (Critical)
Description:CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2011-0083
CVE-2011-0085
CVE-2011-2362
CVE-2011-2363
CVE-2011-2364
CVE-2011-2365
CVE-2011-2371
CVE-2011-2373
CVE-2011-2374
CVE-2011-2375
CVE-2011-2376
CVE-2011-2377
CVE-2011-2605
ELSA-2011:0885-01
Platform(s):Oracle Linux 6
Product(s):firefox
xulrunner
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • firefox is earlier than 0:3.6.18-1.el6_1
  • OR xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1
  • OR xulrunner is earlier than 0:1.9.2.18-2.el6_1
  • BACK