CVE-2007-1562
Last modified
CVE-2007-1562 is a vulnerability of currently unknown severity. The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.. EPSS estimates a 13.85% chance of exploitation in the next 30 days.
Description
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 1.5, < 1.5.0.11 |
| Mozilla | Firefox | >= 2.0, < 2.0.0.3 |
| Canonical | Ubuntu Linux | 5.10 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
References
- http://secunia.com/advisories/25476Third Party Advisory
- http://secunia.com/advisories/25490Third Party Advisory
- http://secunia.com/advisories/25858Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0400.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0402.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/463501/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/470172/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23082Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017800Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-443-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1034Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370559Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33119Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1157Broken Link
- https://issues.rpath.com/browse/RPL-1424Broken Link
- http://secunia.com/advisories/25476Third Party Advisory
- http://secunia.com/advisories/25490Third Party Advisory
- http://secunia.com/advisories/25858Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0400.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0402.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/463501/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/470172/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23082Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017800Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-443-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1034Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370559Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33119Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1157Broken Link
- https://issues.rpath.com/browse/RPL-1424Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1562?
How severe is CVE-2007-1562?
How do I fix CVE-2007-1562?
Are you affected by CVE-2007-1562?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
