LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):firefox, thunderbird CVE #(s):CVE-2012-4201 CVE-2012-4202 CVE-2012-4207 CVE-2012-4209 CVE-2012-4210 CVE-2012-4214 CVE-2012-4215 CVE-2012-4216 CVE-2012-5829 CVE-2012-5830 CVE-2012-5833 CVE-2012-5835 CVE-2012-5839 CVE-2012-5840 CVE-2012-5841 CVE-2012-5842
Created:November 21, 2012 Updated:January 8, 2013
Description: From the Red Hat advisory:

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-4214, CVE-2012-4215, CVE-2012-4216, CVE-2012-5829, CVE-2012-5830, CVE-2012-5833, CVE-2012-5835, CVE-2012-5839, CVE-2012-5840, CVE-2012-5842)

A buffer overflow flaw was found in the way Firefox handled GIF (Graphics Interchange Format) images. A web page containing a malicious GIF image could cause Firefox to crash or, possibly, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-4202)

A flaw was found in the way the Style Inspector tool in Firefox handled certain Cascading Style Sheets (CSS). Running the tool (Tools -> Web Developer -> Inspect) on malicious CSS could result in the execution of HTML and CSS content with chrome privileges. (CVE-2012-4210)

A flaw was found in the way Firefox decoded the HZ-GB-2312 character encoding. A web page containing malicious content could cause Firefox to run JavaScript code with the permissions of a different website. (CVE-2012-4207)

A flaw was found in the location object implementation in Firefox. Malicious content could possibly use this flaw to allow restricted content to be loaded by plug-ins. (CVE-2012-4209)

A flaw was found in the way cross-origin wrappers were implemented. Malicious content could use this flaw to perform cross-site scripting attacks. (CVE-2012-5841)

A flaw was found in the evalInSandbox implementation in Firefox. Malicious content could use this flaw to perform cross-site scripting attacks. (CVE-2012-4201)

Alerts:
Red Hat RHSA-2012:1482-01 2012-11-20
Red Hat RHSA-2012:1483-01 2012-11-20
Mandriva MDVSA-2012:173 2012-11-21
Oracle ELSA-2012-1482 2012-11-21
Oracle ELSA-2012-1483 2012-11-21
Scientific Linux SL-fire-20121121 2012-11-21
Scientific Linux SL-thun-20121121 2012-11-21
CentOS CESA-2012:1482 2012-11-22
CentOS CESA-2012:1482 2012-11-22
CentOS CESA-2012:1483 2012-11-22
CentOS CESA-2012:1483 2012-11-22
Fedora FEDORA-2012-18683 2012-11-22
Fedora FEDORA-2012-18683 2012-11-22
Fedora FEDORA-2012-18683 2012-11-22
Fedora FEDORA-2012-18683 2012-11-22
Fedora FEDORA-2012-18683 2012-11-22
Oracle ELSA-2012-1482 2012-11-21
Slackware SSA:2012-326-01 2012-11-21
Slackware SSA:2012-326-02 2012-11-21
Slackware SSA:2012-326-03 2012-11-21
Ubuntu USN-1638-1 2012-11-21
Ubuntu USN-1636-1 2012-11-21
Ubuntu USN-1638-2 2012-11-21
Mageia MGASA-2012-0342 2012-11-23
Mageia MGASA-2012-0343 2012-11-23
openSUSE openSUSE-SU-2012:1583-1 2012-11-28
openSUSE openSUSE-SU-2012:1584-1 2012-11-28
openSUSE openSUSE-SU-2012:1585-1 2012-11-28
openSUSE openSUSE-SU-2012:1586-1 2012-11-28
SUSE SUSE-SU-2012:1592-1 2012-11-29
Ubuntu USN-1638-3 2012-12-03
Fedora FEDORA-2012-18952 2012-12-04
Fedora FEDORA-2012-18931 2012-12-04
Mageia MGASA-2012-0353 2012-12-07
Debian DSA-2583-1 2012-12-08
Debian DSA-2584-1 2012-12-08
Debian DSA-2588-1 2012-12-16
Gentoo 201301-01 2013-01-07
openSUSE openSUSE-SU-2013:0175-1 2013-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds