|
|
| |
|
| |
mozilla: multiple vulnerabilities
| Package(s): | firefox |
CVE #(s): | CVE-2012-3977
CVE-2012-3987
|
| Created: | October 17, 2012 |
Updated: | October 17, 2012 |
| Description: |
From the SUSE advisory:
CVE-2012-3977: Security researchers
Thai Duong and Juliano Rizzo reported that SPDY's request
header compression leads to information leakage, which can
allow the extraction of private data such as session
cookies, even over an encrypted SSL connection. (This does
not affect Firefox 10 as it does not feature the SPDY
extension. It was silently fixed for Firefox 15.)
CVE-2012-3987: Security researcher
Warren He reported that when a page is transitioned into
Reader Mode in Firefox for Android, the resulting page has
chrome privileges and its content is not thoroughly
sanitized. A successful attack requires user enabling of
reader mode for a malicious page, which could then perform
an attack similar to cross-site scripting (XSS) to gain the
privileges allowed to Firefox on an Android device. This
has been fixed by changing the Reader Mode page into an
unprivileged page. |
| Alerts: |
|
( Log in to post comments)
|
|
|