Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > ÓʼþÈí¼þ©¶´ > Mozilla Firefox/SeaMonkey/Thunderbird¶à¸öÔ¶³Ì°²È«Â©¶´ > ÕýÎÄ

Mozilla Firefox/SeaMonkey/Thunderbird¶à¸öÔ¶³Ì°²È«Â©¶´

³ö´¦£ºÂÌÃ˿Ƽ¼ ×÷ÕߣºÂÌÃ˿Ƽ¼ ʱ¼ä£º2007-2-27 9:32:37
·¢²¼ÈÕÆÚ£º2007-02-23
¸üÐÂÈÕÆÚ£º2007-02-25

ÊÜÓ°Ïìϵͳ£º
Mozilla Firefox <= 2.0.0.1
Mozilla Firefox <= 1.5.0.9
Mozilla Thunderbird <= 1.5.0.9
Mozilla SeaMonkey <= 1.0.7
²»ÊÜÓ°Ïìϵͳ£º
Mozilla Firefox 2.0.0.2
Mozilla Firefox 1.5.0.10
Mozilla Thunderbird 1.5.0.10
Mozilla SeaMonkey 1.0.8
ÃèÊö£º
BUGTRAQ  ID: 22694
CVE(CAN) ID: CVE-2007-0775,CVE-2007-0776,CVE-2007-0777,CVE-2007-0995,CVE-2007-0778,CVE-2007-0779,CVE-2007-0780,CVE-2007-0008,CVE-2007-0009,CVE-2007-0996

Mozilla Firefox/SeaMonkey/Thunderbird¶¼ÊÇMozilla·¢²¼µÄWEBä¯ÀÀÆ÷ºÍÓʼþÐÂÎÅ×é¿Í»§¶Ë²úÆ·¡£

ÉÏÊö²úÆ·ÖдæÔÚ¶à¸ö°²È«Â©¶´£¬¾ßÌåÈçÏ£º

1) ´¦Àílocations.hostname DOMÊôÐÔʱµÄ©¶´¿ÉÄܵ¼ÖÂÈÆ¹ýijЩ°²È«ÏÞÖÆ¡£

2) ÍøÂ簲ȫ·þÎñ£¨NSS£©´úÂëÔÚ´¦ÀíSSLv2·þÎñÆ÷ÏûϢʱ´æÔÚÕûÊýÏÂÒç´íÎó¡£Èç¹ûÖ¤ÊéµÄ¹«Ô¿¹ýСÎÞ·¨¼ÓÃÜMaster SecretµÄ»°£¬ÔòÓû§Ê¹ÓÃÁ˸ÃÖ¤Êé¾Í»á´¥·¢¶ÑÒç³ö£¬µ¼ÖÂÖ´ÐÐÈÎÒâ´úÂë¡£

×¢Ò⣺Firefox 2.xÖÐĬÈϽûÓÃSSLv2£¬½öÔÚÓû§ÐÞ¸ÄÁËÒþ²ØµÄÄÚ²¿NSSÉèÖÃÖØÐÂÆôÓÃSSLv2Ö§³ÖµÄÇé¿öϲŻá³öÏÖÕâ¸ö©¶´¡£

3) Èç¹ûÕ¾µã°üº¬µÄ֡ʹÓÃ"data:" URI×öΪÀ´Ô´µÄ»°£¬Ôò¹¥»÷Õß¿ÉÒÔ¶ÔÕâÑùµÄÕ¾µãÖ´ÐпçÕ¾½Å±¾¹¥»÷¡£

4) Èç¹û°üº¬ÓжñÒâ½Å±¾´úÂëµÄ±¾µØ±£´æÎļþµÄÍêÕû·¾¶ÊÇÒÑÖªµÄ»°£¬¾Í¿ÉÄÜ´ò¿ª°üº¬Óб¾µØÎļþµÄ´°¿Ú£¬ÇÔÈ¡ÄÚÈÝ¡£¹¥»÷Õß¿ÉÒÔ½áºÏÎ±Ëæ»úÊýÉú³ÉÆ÷ÖÖ×ÓÖеÄȱÏÝÀûÓÃÕâ¸ö©¶´£¬µ¼Ö½«ÏÂÔØÎļþ±£´æµ½ÓпÉÔ¤²âÃû³ÆµÄÁÙʱÎļþÖС£

5) ¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆµÄ×Ô¶¨Òå¹â±ê£¬Í¨¹ý¿ØÖÆCSS3ÈȵãÊôÐÔÆÛÆ­ä¯ÀÀÆ÷UIÔªËØ£¬ÈçÖ÷»úÃû»ò°²È«±êʶ·û¡£

6) Á½¸öwebÒ³ÃæÔÚ´ÅÅÌ»º³åÖпÉÄܳåÍ»£¬µ¼Ö½«Ò»¸öÎĵµµÄÒ»²¿·Ö¸½¼Óµ½ÁíÒ»¸öÎĵµÉÏ£¬ÕâÑùÓû§¾Í¿ÉÄÜ´ÓÕ¾µã»ñµÃÃô¸ÐÐÅÏ¢¡£

7) ÔÚ´¦ÀíHTML±êÇ©ÊôÐÔÃûÖÐÎÞЧÍÏβ×Ö·ûʱ£¬»òÕßÈç¹û×ÓÖ¡¼Ì³ÐÁËÆä¸¸´°¿ÚµÄ×Ö·û¼¯µÄÇé¿öÏ´¦ÀíUTF-7ÄÚÈÝʱ£¬Mozilla½âÎöÆ÷Öеĸ÷ÖÖ´íÎó¿ÉÄܵ¼Ö¿çÕ¾½Å±¾¹¥»÷¡£

8) ¿ÚÁî¹ÜÀíÆ÷ÖеÄ©¶´¿ÉÄܵ¼ÖµöÓã¹¥»÷¡£

9) ²¼¾ÖÒýÇæ¡¢JavaScriptÒýÇæºÍSVGÖдæÔÚ¶à¸öÄÚ´æÆÆ»µ´íÎ󣬯äÖÐһЩ¿ÉÄܵ¼ÖÂÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

<*À´Ô´£ºJesse Ruderman £¨jruderman@gmail.com£©
        Martijn Wargers
        Olli Pettay
        Tom Ferris £¨tommy@security-protocols.com£©
        Brian Crowder
        Igor Bukanov
        Johnny Stenback
        moz_bug_r_a4 £¨moz_bug_r_a4@yahoo.com£©
        shutdown £¨shutdown@flashmail.com£©
        Aad
        David Eckel
  
  Á´½Ó£ºhttp://www.mozilla.org/security/announce/2007/mfsa2007-06.html
        http://www.mozilla.org/security/announce/2007/mfsa2007-05.html
        http://www.mozilla.org/security/announce/2007/mfsa2007-04.html
        http://www.mozilla.org/security/announce/2007/mfsa2007-03.html
        http://www.mozilla.org/security/announce/2007/mfsa2007-02.html
        http://www.mozilla.org/security/announce/2007/mfsa2007-01.html
        http://secunia.com/advisories/24205/
        http://secunia.com/advisories/24253/
        http://secunia.com/advisories/24252/
        http://secunia.com/advisories/24238/
        http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483
        http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482
*>

½¨Ò飺
ÁÙʱ½â¾ö·½·¨£º

* ½ûÓÃJavaScript
* ÔÚ¡°Æ«ºÃ¡±ÖÐÁÙʱ½«´ÅÅÌ»º´æ´óСÉèÖÃΪ0
* ×Ô¶¨Òåä¯ÀÀÆ÷µÄÍâ¹Û
* ²»Òª´ò¿ªµ¯³ö´°¿Ú
* ½ûÓÃSSLv2ЭÒé

³§É̲¹¶¡£º

Mozilla
-------
Ŀǰ³§ÉÌÒѾ­·¢²¼ÁËÉý¼¶²¹¶¡ÒÔÐÞ¸´Õâ¸ö°²È«ÎÊÌ⣬Çëµ½³§É̵ÄÖ÷Ò³ÏÂÔØ£º

http://www.mozilla.com/products/download.html?product=firefox-1.5.0.10&os=win&lang=en-US
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.2&os=linux&lang=en-US
http://www.mozilla.com/products/download.html?product=thunderbird-1.5.0.10&os=linux&lang=en-US

Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • SurgeMail IMAP·þÎñAPPENDÃüÁîÔ¶³ÌÒç³ö©¶´
  • Horde MIME¸½¼þÎļþÃû¿çÕ¾½Å±¾Â©¶´
  • FoxmailÓʼþ¿Í»§¶Ëmailto»º³åÇøÒç³ö©¶´
  • ÑÅ»¢µçÓÊÆØ°²È«Â©¶´ ¿Éµ¼ÖÂÓû§ÃÜÂ뱻й¶
  • Softalk Mail Server APPENDÃüÁîÔ¶³Ì¾Ü¾ø·þÎñ©¶´
  • IBM Lotus Quickr¶à¸ö¿çÕ¾½Å±¾Ö´ÐЩ¶´
  • MailScan Web¹ÜÀí½Ó¿Ú¶à¸ö°²È«Â©¶´
  • MailEnable IMAPÁ¬½ÓÔ¶³Ì¾Ü¾ø·þÎñ©¶´
  • Sophos²úÆ·MIME¸½¼þ´¦Àí¾Ü¾ø·þÎñ©¶´
  • ͸¹ýDNS©¶´·¢ÏÖÕß ¿´°²È«×¨¼ÒÖ°Òµ²ÙÊØ
  • GmailÓÊÏäй¦Äܾª±¬Â©¶´ ºÚ¿ÍËÅ»ú¶ø¶¯
  • Commtouch·´À¬»øÓʼþÆóÒµÍø¹ØPARAMS²ÎÊý¿çÕ¾½Å±¾Â©¶´
  • Exchange Server 2003 ÖеÄÈõµã»áµ¼ÖÂȨÏÞÌáÉý
  • ¸ü°²È«Îȶ¨!¿ìÏÂÔØÎ¢ÈíISA 2000 SP2
  • MDaemon 7.2·¢ÏÖȨÏÞÌáÉý©¶´
  • Exchange 2003 Server·¢²¼Ð²¹¶¡KB883543
  • ΢Èí·¢²¼¹ØÓÚExchange©¶´½ô¼±¹«¸æ
  • MS05-021:Exchange Server©¶´Ô¶³ÌÖ´ÐдúÂë
  • WebAdmin 3.0.2 ¿çÕ¾½Å±¾¡¢HTML×¢È밲ȫ©¶´
  • Imail Server IMAP EXAMINEÃüÁ³åÇøÒç³ö©¶´
  • Open WebMail Email´æÔÚÍ·×Ö¶ÎHTML´úÂë×¢Èë©¶´
  • ΢Èí·¢²¼¹ØÓÚExchange 5.5 ©¶´¸üй«¸æ
  • IMail 8.13Ô¶³ÌDELETEÃüÁ³åÇøÒç³ö©¶´
  • MS04-035:SMTPÖа²È«Â©¶´¿ÉÄÜÔÊÐíÖ´ÐÐÔ¶³Ì´úÂë
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ