LWN.net Logo

Mozilla products: multiple vulnerabilities

Package(s):firefox thunderbird seamonkey CVE #(s):CVE-2012-0451 CVE-2012-0455 CVE-2012-0456 CVE-2012-0457 CVE-2012-0458 CVE-2012-0459 CVE-2012-0460 CVE-2012-0461 CVE-2012-0462 CVE-2012-0464
Created:March 14, 2012 Updated:July 23, 2012
Description: The Red Hat advisory nicely describes the latest round of Mozilla vulnerabilities, most of which are fixed in the Firefox 11 and Thunderbird 11 releases:

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-0461, CVE-2012-0462, CVE-2012-0464)

Two flaws were found in the way Firefox parsed certain Scalable Vector Graphics (SVG) image files. A web page containing a malicious SVG image file could cause an information leak, or cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-0456, CVE-2012-0457)

A flaw could allow a malicious site to bypass intended restrictions, possibly leading to a cross-site scripting (XSS) attack if a user were tricked into dropping a "javascript:" link onto a frame. (CVE-2012-0455)

It was found that the home page could be set to a "javascript:" link. If a user were tricked into setting such a home page by dragging a link to the home button, it could cause Firefox to repeatedly crash, eventually leading to arbitrary code execution with the privileges of the user running Firefox. (CVE-2012-0458)

A flaw was found in the way Firefox parsed certain web content containing "cssText". A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-0459)

It was found that by using the DOM fullscreen API, untrusted content could bypass the mozRequestFullscreen security protections. A web page containing malicious web content could exploit this API flaw to cause user interface spoofing. (CVE-2012-0460)

A flaw was found in the way Firefox handled pages with multiple Content Security Policy (CSP) headers. This could lead to a cross-site scripting attack if used in conjunction with a website that has a header injection flaw. (CVE-2012-0451)

Alerts:
Red Hat RHSA-2012:0387-01 2012-03-14
CentOS CESA-2012:0387 2012-03-14
CentOS CESA-2012:0388 2012-03-14
Red Hat RHSA-2012:0388-01 2012-03-14
CentOS CESA-2012:0387 2012-03-14
CentOS CESA-2012:0388 2012-03-14
Oracle ELSA-2012-0387 2012-03-15
Oracle ELSA-2012-0387 2012-03-15
Oracle ELSA-2012-0388 2012-03-15
Debian DSA-2433-1 2012-03-15
Mandriva MDVSA-2012:031 2012-03-17
Ubuntu USN-1400-1 2012-03-16
Ubuntu USN-1400-2 2012-03-16
Fedora FEDORA-2012-3996 2012-03-17
Fedora FEDORA-2012-3996 2012-03-17
Fedora FEDORA-2012-3996 2012-03-17
Fedora FEDORA-2012-3996 2012-03-17
Fedora FEDORA-2012-3996 2012-03-17
Fedora FEDORA-2012-3996 2012-03-17
Ubuntu USN-1401-1 2012-03-19
Mandriva MDVSA-2012:032 2012-03-20
Debian DSA-2437-1 2012-03-21
Ubuntu USN-1400-3 2012-03-21
Scientific Linux SL-thun-20120321 2012-03-21
Scientific Linux SL-fire-20120321 2012-03-21
Ubuntu USN-1401-2 2012-03-23
openSUSE openSUSE-SU-2012:0417-1 2012-03-27
SUSE SUSE-SU-2012:0425-1 2012-03-29
SUSE SUSE-SU-2012:0424-1 2012-03-28
Ubuntu USN-1400-4 2012-04-03
Mandriva MDVSA-2012:032-1 2012-04-17
Debian DSA-2458-1 2012-04-24
Ubuntu USN-1400-5 2012-04-20
openSUSE openSUSE-SU-2012:0567-1 2012-04-27
Mageia MGASA-2012-0176 2012-07-21
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds