CVE-2007-1562
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 13.85% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdfBroken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742Broken Link
- http://secunia.com/advisories/25476Third Party Advisory
- http://secunia.com/advisories/25490Third Party Advisory
- http://secunia.com/advisories/25858Third Party Advisory
- http://www.mozilla.org/security/announce/2007/mfsa2007-11.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2007_36_mozilla.htmlBroken Link
- http://www.openwall.com/lists/oss-security/2020/12/09/1
- http://www.redhat.com/support/errata/RHSA-2007-0400.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0402.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/463501/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/470172/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23082Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017800Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-443-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1034Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370559Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33119Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1157Broken Link
- https://issues.rpath.com/browse/RPL-1424Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11431Third Party Advisory
- http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdfBroken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742Broken Link
- http://secunia.com/advisories/25476Third Party Advisory
- http://secunia.com/advisories/25490Third Party Advisory
- http://secunia.com/advisories/25858Third Party Advisory
- http://www.mozilla.org/security/announce/2007/mfsa2007-11.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2007_36_mozilla.htmlBroken Link
- http://www.openwall.com/lists/oss-security/2020/12/09/1
- http://www.redhat.com/support/errata/RHSA-2007-0400.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.