Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1729-1 | third party advisory vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=830614 | issue tracking patch vendor advisory |
http://www.ubuntu.com/usn/USN-1729-2 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html | mailing list third party advisory vendor advisory |
http://www.mozilla.org/security/announce/2013/mfsa2013-23.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html | mailing list third party advisory vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17097 | vdb entry third party advisory signature |