HTTP: Mozilla Firefox SVG Data Processing

This signature detects attempts to expoit a known vulnerability in Mozilla Firefox. An attacker can create a malicious Web site with Web pages containing dangerous SVG, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

The Mozilla Foundation has released multiple security advisories for various vulnerabilities in Firefox, Thunderbird, and SeaMonkey. Attackers can exploit these issues to bypass same-origin restrictions, obtain potentially sensitive information, and execute arbitrary script code with elevated privileges; other attacks are also possible.

Affected Products

Red_hat fedora

References

BugTraq: 33990

CVE: CVE-2009-0771

Short Name
HTTP:STC:MOZILLA:SVG-DATA
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2009-0771 Data Firefox Mozilla Processing SVG bid:33990
Release Date
09/22/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Red_hat

Suse

Mozilla

Avaya

Pardus

Slackware

Ubuntu

Mandriva

Debian

CVSS Score

10.0

Found a potential security threat?