Skip to main content

Mozilla Products Multiple Vulnerabilities

Last Update Date: 12 Oct 2012 Release Date: 11 Oct 2012 3942 Views

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities reported in Mozilla Firefox, Seamonkey and Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system, inject scripting code, and spoof portions of the page.

  1. A remote user can create specially crafted content that, when loaded by the target user, will trigger a memory corruption error, use-after-free memory error, buffer overflow, access control error, or other flaw and execute arbitrary code on the target system. The code will run with the privileges of the target user.
  2. A remote user can cause arbitrary scripting code to be executed by the target user's browser. The code will run in the security context of an arbitrary site. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.
  3. A remote user can exploit a flaw in the processing of <select> elements to spoof portions of a page.
  4. A remote user can create specially crafted HTML that, when loaded by the target user, will access recently visited URLs and URL parameters. Only version 16.0 is affected.

Impact

  • Remote Code Execution
  • Information Disclosure
  • Spoofing
  • Data Manipulation

System / Technologies affected

  • Mozilla Firefox versions prior to 16.0.1
  • Mozilla Seamonkey versions prior to 2.13
  • Mozilla Thunderbird versions prior to ESR 10.0.8, 16.0.1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix for Mozilla Firefox (ESR 10.0.8; 16.0.1).
  • The vendor has issued a fix for Mozilla Seamonkey (2.13).
  • The vendor has issued a fix for Mozilla Thunderbird (ESR 10.0.8; 16.0.1).

Vulnerability Identifier


Source


Related Link