Mozilla Firefox Security Bypass Vulnerability
2015年7月21日
危険度: 中
CVE識別番号: CVE-2008-5012
情報公開日: 7 21, 2015
概要
Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1003044
Trend Micro Deep Security DPI Rule Name: 1003044 - Mozilla Firefox Security Bypass Vulnerability
影響を受けるソフトウェア
- mozilla firefox 0.10
- mozilla firefox 0.10.1
- mozilla firefox 0.8
- mozilla firefox 0.9
- mozilla firefox 0.9.1
- mozilla firefox 0.9.2
- mozilla firefox 0.9.3
- mozilla firefox 0.9_rc
- mozilla firefox 1.0
- mozilla firefox 1.0.1
- mozilla firefox 1.0.2
- mozilla firefox 1.0.3
- mozilla firefox 1.0.4
- mozilla firefox 1.0.6
- mozilla firefox 1.0.5
- mozilla firefox 1.0.7
- mozilla firefox 1.0.8
- mozilla firefox 1.5
- mozilla firefox 1.5.0.1
- mozilla firefox 1.5.0.10
- mozilla firefox 1.5.0.11
- mozilla firefox 1.5.0.12
- mozilla firefox 1.5.0.2
- mozilla firefox 1.5.0.3
- mozilla firefox 1.5.0.4
- mozilla firefox 1.5.0.5
- mozilla firefox 1.5.0.6
- mozilla firefox 1.5.0.7
- mozilla seamonkey 1.0.5
- mozilla seamonkey 1.0.6
- mozilla seamonkey 1.0.7
- mozilla seamonkey 1.0.8
- mozilla seamonkey 1.0.9
- mozilla seamonkey 1.0.99
- mozilla seamonkey 1.1
- mozilla seamonkey 1.1.1
- mozilla seamonkey 1.1.10
- mozilla seamonkey 1.1.11
- mozilla seamonkey 1.1.12
- mozilla seamonkey 1.1.2
- mozilla seamonkey 1.1.3
- mozilla seamonkey 1.1.4
- mozilla seamonkey 1.1.5
- mozilla seamonkey 1.1.6
- mozilla seamonkey 1.1.7
- mozilla seamonkey 1.1.8
- mozilla seamonkey 1.1.9
- mozilla thunderbird 0.1
- mozilla thunderbird 0.2
- mozilla thunderbird 0.3
- mozilla thunderbird 0.4
- mozilla thunderbird 0.5
- mozilla firefox 1.5.0.8
- mozilla firefox 1.5.0.9
- mozilla firefox 1.5.1
- mozilla firefox 1.5.2
- mozilla firefox 1.5.3
- mozilla firefox 1.5.4
- mozilla firefox 1.5.6
- mozilla firefox 1.5.7
- mozilla firefox 1.5.8
- mozilla firefox 1.8
- mozilla firefox 2.0
- mozilla firefox 2.0.0.10
- mozilla firefox 2.0.0.11
- mozilla firefox 2.0.0.12
- mozilla firefox 2.0.0.13
- mozilla firefox 2.0.0.14
- mozilla firefox 2.0.0.15
- mozilla firefox 2.0.0.16
- mozilla firefox 2.0.0.17
- mozilla firefox 2.0.0.2
- mozilla firefox 2.0.0.3
- mozilla firefox 2.0.0.5
- mozilla firefox 2.0.0.6
- mozilla firefox 2.0.0.7
- mozilla firefox 2.0.0.8
- mozilla firefox 2.0.0.9
- mozilla seamonkey 1.0
- mozilla seamonkey 1.0.1
- mozilla seamonkey 1.0.2
- mozilla seamonkey 1.0.3
- mozilla seamonkey 1.0.4
- mozilla thunderbird 0.6
- mozilla thunderbird 0.7
- mozilla thunderbird 0.7.1
- mozilla thunderbird 0.7.2
- mozilla thunderbird 0.7.3
- mozilla thunderbird 0.8
- mozilla thunderbird 0.9
- mozilla thunderbird 1.0
- mozilla thunderbird 1.0.1
- mozilla thunderbird 1.0.2
- mozilla thunderbird 1.0.3
- mozilla thunderbird 1.0.4
- mozilla thunderbird 1.0.5
- mozilla thunderbird 1.0.6
- mozilla thunderbird 1.0.7
- mozilla thunderbird 1.0.8
- mozilla thunderbird 1.5
- mozilla thunderbird 1.5.0.1
- mozilla thunderbird 1.5.0.10
- mozilla thunderbird 1.5.0.11
- mozilla thunderbird 1.5.0.2
- mozilla thunderbird 1.5.0.3
- mozilla thunderbird 1.5.0.4
- mozilla thunderbird 1.5.0.6
- mozilla thunderbird 1.5.0.7
- mozilla thunderbird 1.5.0.8
- mozilla thunderbird 1.5.0.9
- mozilla thunderbird 1.5.1
- mozilla thunderbird 1.5.2
- mozilla thunderbird 1.7.1
- mozilla thunderbird 1.7.3
- mozilla thunderbird 2.0.0.0
- mozilla thunderbird 2.0.0.1
- mozilla thunderbird 2.0.0.11
- mozilla thunderbird 2.0.0.12
- mozilla thunderbird 2.0.0.13
- mozilla thunderbird 2.0.0.14
- mozilla thunderbird 2.0.0.15
- mozilla thunderbird 2.0.0.16
- mozilla thunderbird 2.0.0.17
- mozilla thunderbird 2.0.0.2
- mozilla thunderbird 2.0.0.3
- mozilla thunderbird 2.0.0.4