|
|
| |
|
| |
firefox: multiple vulnerabilities
| Package(s): | Mozilla Firefox |
CVE #(s): | CVE-2012-5837
CVE-2012-4206
|
| Created: | November 29, 2012 |
Updated: | December 5, 2012 |
| Description: |
From the Mozilla advisory:
MFSA 2012-102 / CVE-2012-5837: Security researcher
Masato Kinugawa reported that when script is entered into
the Developer Toolbar, it runs in a chrome privileged
context. This allows for arbitrary code execution or
cross-site scripting (XSS) if a user can be convinced to
paste malicious code into the Developer Toolbar.
MFSA 2012-98 / CVE-2012-4206: Security researcher
Robert Kugler reported that when a specifically named DLL
file on a Windows computer is placed in the default
downloads directory with the Firefox installer, the Firefox
installer will load this DLL when it is launched. In
circumstances where the installer is run by an
administrator privileged account, this allows for the
downloaded DLL file to be run with administrator
privileges. This can lead to arbitrary code execution from
a privileged account.
|
| Alerts: |
|
( Log in to post comments)
|
|
|