Vulnerability Name: | CVE-2009-5017 (CCN-63259) | ||||||||||||||||||||||||
Assigned: | 2009-08-21 | ||||||||||||||||||||||||
Published: | 2009-08-21 | ||||||||||||||||||||||||
Updated: | 2010-12-01 | ||||||||||||||||||||||||
Summary: | Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-5017 Source: CONFIRM Type: UNKNOWN http://hg.mozilla.org/releases/mozilla-1.9.2/rev/e42c563313a0 Source: CCN Type: RHSA-2010-0500 Critical: firefox security, bug fix, and enhancement update Source: CCN Type: RHSA-2010-0501 Critical: firefox security, bug fix, and enhancement update Source: MISC Type: Exploit http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html Source: CCN Type: Mozilla Web site Firefox - Rediscover the web Source: CCN Type: Bugzilla@Mozilla Bug 511859 Utf8ToOneUcs4Char in jsstr.cpp ,overlong UTF-8 seqence detection problem. Source: CONFIRM Type: Patch https://bugzilla.mozilla.org/show_bug.cgi?id=511859 Source: CONFIRM Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=522634 Source: XF Type: UNKNOWN firefox-utf8-security-bypass(63259) | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |