LWN.net Logo

mozilla: privilege escalation

Package(s):firefox, thunderbird, seamonkey CVE #(s):CVE-2013-1726
Created:September 30, 2013 Updated:October 2, 2013
Description: From the CVE entry:

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

Alerts:
Gentoo 201309-23 2013-09-27
SUSE SUSE-SU-2013:1497-1 2013-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds