Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-17988 | DTBF003 | SV-19509r1_rule | DCMC-1 | High |
Description |
---|
Use of versions of an application which are not supported by the vendor are not permitted. Vendors respond to security flaws with updates and patches. These updates are not available for unsupported version which can leave the application vulnerable to attack. |
STIG | Date |
---|---|
Mozilla Firefox | 2015-06-30 |
Check Text ( C-20617r1_chk ) |
---|
Method 1: View the following registry key: HKLM\Software\Mozilla\Mozilla Firefox\CurrentVersion Method 2: Search for the firefox.exe file using the search feature of the operating system. Examine the files properties for the product version (not the file version. For Windows OS, determine the version of the file by examining navigating to Properties/Version/Product Version. Examine for all instances of firefox.exe that are present on the endpoint. Criteria: If the version number of the firefox.exe file is less than 3.x.x, then this is a Finding. |
Fix Text (F-18550r1_fix) |
---|
Upgrade the version of the browser to an approved version by obtaining software from the vendor or other trusted source. |