toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Mar 25, 2010 |
| Mfsa2010 15 | — | Upgrade to Mozilla Firefox version 3.6.2 | Jun 14, 2012 | Mar 25, 2010 |
| Suse | — | Upgrade mozilla-xulrunner192-gnomeUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192-translations-32bitUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-translations | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub