Vulnerability Name: | CVE-2010-3171 (CCN-61792) | ||||||||
Assigned: | 2010-09-14 | ||||||||
Published: | 2010-09-14 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." Note: this vulnerability exists because of an incorrect fix for CVE-2008-5913. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:F/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20100914 New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1" Source: CCN Type: Sun Security Blog 07 Jan 2011 Multiple Vulnerabilities in Mozilla Firefox Source: CONFIRM Type: UNKNOWN http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox Source: MITRE Type: CNA CVE-2010-3171 Source: CCN Type: SA42867 Oracle Solaris Firefox Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 42867 Source: CCN Type: Mozilla Web site Firefox Source: CCN Type: OSVDB ID: 68047 Mozilla Firefox JavaScript Implementation js_InitRandom Function Multiple Pointer RNG Seeding Weakness Source: BID Type: Exploit 43222 Source: CCN Type: BID-43222 Mozilla Firefox 'Math.random()' Cross Domain Information Disclosure Vulnerability Source: CCN Type: Amit Klein Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1 Source: MISC Type: Exploit http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdf Source: VUPEN Type: UNKNOWN ADV-2011-0061 Source: MISC Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=577512 Source: XF Type: UNKNOWN firefox-mathrandom-info-disclosure(61792) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7370 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |