Vulnerability Name:

CVE-2010-3399 (CCN-61855)

Assigned:2010-08-17
Published:2010-08-17
Updated:2017-09-19
Summary:The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2010-3171.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Obtain Information
References:Source: BUGTRAQ
Type: UNKNOWN
20100914 New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1"

Source: CCN
Type: Sun Security Blog 07 Jan 2011
Multiple Vulnerabilities in Mozilla Firefox

Source: CONFIRM
Type: UNKNOWN
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox

Source: MITRE
Type: CNA
CVE-2010-3399

Source: CCN
Type: SA42867
Oracle Solaris Firefox Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
42867

Source: CCN
Type: Mozilla Web site
Firefox

Source: MISC
Type: Exploit
http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdf

Source: VUPEN
Type: UNKNOWN
ADV-2011-0061

Source: CCN
Type: Bugzilla@Mozilla Bug 475585
Re-seed Math.random() for each window/frame/context

Source: MISC
Type: UNKNOWN
https://bugzilla.mozilla.org/show_bug.cgi?id=475585

Source: MISC
Type: UNKNOWN
https://bugzilla.mozilla.org/show_bug.cgi?id=577512

Source: XF
Type: UNKNOWN
firefox-context-pointer-info-disclosure(61855)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:7598

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:10::64bit:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:7598
    V
    Vulnerability in js_InitRandom function in the JavaScript implementation in Mozilla Firefox
    2014-10-06
    BACK
    mozilla firefox 3.5.10
    mozilla firefox 3.5.11
    mozilla firefox 3.6.4
    mozilla firefox 3.6.6
    mozilla firefox 3.6.7
    mozilla firefox 3.6.8
    mozilla firefox 4.0 beta1
    mozilla firefox 3.6.4
    mozilla firefox 3.6.6
    mozilla firefox 3.5.10
    mozilla firefox 3.6.7
    mozilla firefox 3.6.8
    mozilla firefox 3.5.11
    sun solaris 10