Mozilla Firefox SSL Spoofing Vulnerability

  Severity: LOW
  CVE Identifier: CVE-2010-2751
  Advisory Date: FEB 04, 2011

  DESCRIPTION

The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.

  TREND MICRO PROTECTION INFORMATION

Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.

  AFFECTED SOFTWARE AND VERSION

  • mozilla firefox 3.5.1
  • mozilla firefox 3.5.10
  • mozilla firefox 3.5.2
  • mozilla firefox 3.5.3
  • mozilla firefox 3.5.4
  • mozilla firefox 3.5.5
  • mozilla firefox 3.5.6
  • mozilla firefox 3.5.7
  • mozilla firefox 3.5.9
  • mozilla firefox 3.6.1
  • mozilla firefox 3.6.2
  • mozilla firefox 3.6.3
  • mozilla firefox 3.6.4
  • mozilla firefox 3.6.6
  • mozilla seamonkey 1.0
  • mozilla seamonkey 1.0.1
  • mozilla seamonkey 1.0.2
  • mozilla seamonkey 1.0.3
  • mozilla seamonkey 1.0.4
  • mozilla seamonkey 1.0.5
  • mozilla seamonkey 1.0.6
  • mozilla seamonkey 1.0.7
  • mozilla seamonkey 1.0.8
  • mozilla seamonkey 1.0.9
  • mozilla seamonkey 1.1
  • mozilla seamonkey 1.1.1
  • mozilla seamonkey 1.1.10
  • mozilla seamonkey 1.1.11
  • mozilla seamonkey 1.1.12
  • mozilla seamonkey 1.1.13
  • mozilla seamonkey 1.1.14
  • mozilla seamonkey 1.1.15
  • mozilla seamonkey 1.1.16
  • mozilla seamonkey 1.1.17
  • mozilla seamonkey 1.1.18
  • mozilla seamonkey 1.1.19
  • mozilla seamonkey 1.1.2
  • mozilla seamonkey 1.1.3
  • mozilla seamonkey 1.1.4
  • mozilla seamonkey 1.1.5
  • mozilla seamonkey 1.1.6
  • mozilla seamonkey 1.1.7
  • mozilla seamonkey 1.1.8
  • mozilla seamonkey 1.1.9
  • mozilla seamonkey 1.5.0.10
  • mozilla seamonkey 1.5.0.8
  • mozilla seamonkey 1.5.0.9
  • mozilla seamonkey 2.0
  • mozilla seamonkey 2.0.1
  • mozilla seamonkey 2.0.2
  • mozilla seamonkey 2.0.3
  • mozilla seamonkey 2.0.4
  • mozilla seamonkey 2.0.5
  • mozilla seamonkey 2.0a1pre