CVE-2007-1562

CVSS V2 Medium 6.8 CVSS V3 None
Description
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
Overview
  • CVE ID
  • CVE-2007-1562
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2007-03-21T19:19:00
  • Last Modified Date
  • 2020-12-09T10:15:12
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1 OR 1.5 1.5.0.11
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1 OR 2.0 2.0.0.3
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 6.4
References
Reference URL Reference Tags
http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf Broken Link
https://bugzilla.mozilla.org/show_bug.cgi?id=370559 Issue Tracking Vendor Advisory
http://www.mozilla.org/security/announce/2007/mfsa2007-11.html Vendor Advisory
http://www.ubuntu.com/usn/usn-443-1 Third Party Advisory
https://issues.rpath.com/browse/RPL-1157 Broken Link
https://issues.rpath.com/browse/RPL-1424 Broken Link
http://www.redhat.com/support/errata/RHSA-2007-0400.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2007-0402.html Third Party Advisory
http://www.novell.com/linux/security/advisories/2007_36_mozilla.html Broken Link
http://www.securityfocus.com/bid/23082 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1017800 Third Party Advisory VDB Entry
http://secunia.com/advisories/25476 Third Party Advisory
http://secunia.com/advisories/25490 Third Party Advisory
http://secunia.com/advisories/25858 Third Party Advisory
http://www.vupen.com/english/advisories/2007/1034 Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/33119 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11431 Third Party Advisory
http://www.securityfocus.com/archive/1/470172/100/200/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/463501/100/0/threaded Third Party Advisory VDB Entry
http://www.openwall.com/lists/oss-security/2020/12/09/1
History
Created Old Value New Value Data Type Notes
2022-05-10 07:30:52 Added to TrackCVE