Secunia Security Advisory - HP has acknowledged multiple vulnerabilities in Mozilla for HP-UX, which can be exploited by malicious people to bypass certain security restrictions, conduct spoofing and cross-site scripting attacks, and compromise a user's system.
95f159c409d7e113fc74217da636a58aa33f60322b0252ae9f8fce25e3111d50
TITLE:
HP-UX Mozilla Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA17057
VERIFY ADVISORY:
http://secunia.com/advisories/17057/
CRITICAL:
Highly critical
IMPACT:
Security Bypass, Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
HP-UX 11.x
http://secunia.com/product/138/
DESCRIPTION:
HP has acknowledged multiple vulnerabilities in Mozilla for HP-UX,
which can be exploited by malicious people to bypass certain security
restrictions, conduct spoofing and cross-site scripting attacks, and
compromise a user's system.
For more information:
SA15489
SA15551
SA15601
SA16059
SA16767
The vulnerabilities affect HP-UX B.11.00, B.11.11, B.11.22, and
B.11.23.
SOLUTION:
Install version 1.7.11.00 or subsequent, and disable IDN support in
Mozilla.
http://www.hp.com/products1/unix/java/mozilla/index.html
ORIGINAL ADVISORY:
SSRT051040:
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01230
SSRT051041:
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01231
OTHER REFERENCES:
SA15489:
http://secunia.com/advisories/15489/
SA15551:
http://secunia.com/advisories/15551/
SA15601:
http://secunia.com/advisories/15601/
SA16059:
http://secunia.com/advisories/16059/
SA16767:
http://secunia.com/advisories/16767/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------