Vulnerability Name: | CVE-2010-3399 (CCN-61855) | ||||||||
Assigned: | 2010-08-17 | ||||||||
Published: | 2010-08-17 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2010-3171. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20100914 New writeup by Amit Klein (Trusteer): "Cross-domain information leakage in Firefox 3.6.4-3.6.8, Firefox 3.5.10-3.5.11 and Firefox 4.0 Beta1" Source: CCN Type: Sun Security Blog 07 Jan 2011 Multiple Vulnerabilities in Mozilla Firefox Source: CONFIRM Type: UNKNOWN http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox Source: MITRE Type: CNA CVE-2010-3399 Source: CCN Type: SA42867 Oracle Solaris Firefox Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 42867 Source: CCN Type: Mozilla Web site Firefox Source: MISC Type: Exploit http://www.trusteer.com/sites/default/files/Cross_domain_Math_Random_leakage_in_FF_3.6.4-3.6.8.pdf Source: VUPEN Type: UNKNOWN ADV-2011-0061 Source: CCN Type: Bugzilla@Mozilla Bug 475585 Re-seed Math.random() for each window/frame/context Source: MISC Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=475585 Source: MISC Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=577512 Source: XF Type: UNKNOWN firefox-context-pointer-info-disclosure(61855) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7598 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |