Release date:
Last Updated:
Hazard level:
Vulnerability Type: Information Leakage
Threat Type:
Vulnerability introduction:
Mozilla Firefox is a free, open-source browser applicable to Windows, Linux, and MacOS X platforms.
Content Security Policy (CSP) in Mozilla Firefox 4.x to 5 does not allow you to move proxy authentication certificates from the listed request headers. Attackers can obtain sensitive information by reading the report. This vulnerability is related to incorrect host resolutions that occur simultaneously with certain redirection.
Vulnerability announcement:
Currently, the vendor has released an upgrade patch to fix this security issue. Obtain the patch link:
Https://developer.mozilla.org/en/Download_Mozilla_Source_Code
Reference URL:
Source: bugzilla.w.illa.org
Link: https://bugzilla.mozilla.org/show_bug.cgi? Id = 679588
Source: bugzilla.w.illa.org
Link: https://bugzilla.mozilla.org/show_bug.cgi? Id = 664983
Source: www.mozilla.org
Link: http://www.mozilla.org/security/announce/2011/mfsa2011-29.html