LWN.net Logo

unity-firefox-extension: information disclosure

Package(s):unity-firefox-extension CVE #(s):CVE-2012-0958
Created:December 19, 2012 Updated:December 19, 2012
Description:

From the Ubuntu advisory:

It was discovered that unity-firefox-extension bypassed the same origin policy checks in certain circumstances. If a user were tricked into opening a malicious page, an attacker could exploit this to steal confidential data or perform other security-sensitive operations.

Alerts:
Ubuntu USN-1665-1 2012-12-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds