Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2011:139 | vendor advisory |
http://secunia.com/advisories/46315 | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14442 | vdb entry signature |
http://www.mozilla.org/security/announce/2011/mfsa2011-40.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:141 | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=672485 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:142 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00020.html | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2011-10/msg00002.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:140 | vendor advisory |