Rapid7 Vulnerability & Exploit Database

MFSA2010-78 Firefox: Add support for OTS font sanitizer (CVE-2010-3768)

Back to Search

MFSA2010-78 Firefox: Add support for OTS font sanitizer (CVE-2010-3768)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
12/10/2010
Created
07/25/2018
Added
06/14/2012
Modified
02/13/2015

Description

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.

Solution(s)

  • mozilla-firefox-upgrade-3_5_16
  • mozilla-firefox-upgrade-3_6_13

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;