LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):firefox, thunderbird, seamonkey CVE #(s):CVE-2012-4191 CVE-2012-4192
Created:October 15, 2012 Updated:October 17, 2012
Description: From the CVE entries:

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. (CVE-2012-4191)

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193. (CVE-2012-4192)

Alerts:
Ubuntu USN-1611-1 2012-10-12
openSUSE openSUSE-SU-2012:1345-1 2012-10-15
SUSE SUSE-SU-2012:1351-1 2012-10-16
Ubuntu USN-1608-1 2012-10-11
Slackware SSA:2012-285-02 2012-10-11
Slackware SSA:2012-285-01 2012-10-11
Fedora FEDORA-2012-15985 2012-10-12
Fedora FEDORA-2012-15986 2012-10-12
Fedora FEDORA-2012-15986 2012-10-12
Fedora FEDORA-2012-15985 2012-10-12
Mageia MGASA-2012-0353 2012-12-07
Gentoo 201301-01 2013-01-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds