The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.mozilla.org/security/announce/2012/mfsa2012-68.html | vendor advisory |
http://www.securityfocus.com/bid/55311 | vdb entry |
http://www.ubuntu.com/usn/USN-1548-1 | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=770684 | |
http://www.ubuntu.com/usn/USN-1548-2 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16855 | vdb entry signature |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html | vendor advisory |