The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17039 | vdb entry signature |
https://bugzilla.mozilla.org/show_bug.cgi?id=757128 | |
http://www.mozilla.org/security/announce/2012/mfsa2012-66.html | vendor advisory |
http://www.securityfocus.com/bid/55308 | vdb entry |
http://osvdb.org/85005 | vdb entry |
http://www.ubuntu.com/usn/USN-1548-1 | vendor advisory |
http://www.ubuntu.com/usn/USN-1548-2 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html | vendor advisory |