|
|
Subscribe / Log in / New account

mozilla: multiple vulnerabilities

Package(s):firefox, thunderbird CVE #(s):CVE-2012-4201 CVE-2012-4202 CVE-2012-4207 CVE-2012-4209 CVE-2012-4210 CVE-2012-4214 CVE-2012-4215 CVE-2012-4216 CVE-2012-5829 CVE-2012-5830 CVE-2012-5833 CVE-2012-5835 CVE-2012-5839 CVE-2012-5840 CVE-2012-5841 CVE-2012-5842
Created:November 21, 2012 Updated:January 8, 2013
Description: From the Red Hat advisory:

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-4214, CVE-2012-4215, CVE-2012-4216, CVE-2012-5829, CVE-2012-5830, CVE-2012-5833, CVE-2012-5835, CVE-2012-5839, CVE-2012-5840, CVE-2012-5842)

A buffer overflow flaw was found in the way Firefox handled GIF (Graphics Interchange Format) images. A web page containing a malicious GIF image could cause Firefox to crash or, possibly, execute arbitrary code with the privileges of the user running Firefox. (CVE-2012-4202)

A flaw was found in the way the Style Inspector tool in Firefox handled certain Cascading Style Sheets (CSS). Running the tool (Tools -> Web Developer -> Inspect) on malicious CSS could result in the execution of HTML and CSS content with chrome privileges. (CVE-2012-4210)

A flaw was found in the way Firefox decoded the HZ-GB-2312 character encoding. A web page containing malicious content could cause Firefox to run JavaScript code with the permissions of a different website. (CVE-2012-4207)

A flaw was found in the location object implementation in Firefox. Malicious content could possibly use this flaw to allow restricted content to be loaded by plug-ins. (CVE-2012-4209)

A flaw was found in the way cross-origin wrappers were implemented. Malicious content could use this flaw to perform cross-site scripting attacks. (CVE-2012-5841)

A flaw was found in the evalInSandbox implementation in Firefox. Malicious content could use this flaw to perform cross-site scripting attacks. (CVE-2012-4201)

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
openSUSE openSUSE-SU-2013:0175-1 mozilla 2013-01-23
Gentoo 201301-01 firefox 2013-01-07
Debian DSA-2588-1 icedove 2012-12-16
Debian DSA-2584-1 iceape 2012-12-08
Debian DSA-2583-1 iceweasel 2012-12-08
Mageia MGASA-2012-0353 iceape 2012-12-07
Fedora FEDORA-2012-18683 firefox 2012-11-22
CentOS CESA-2012:1483 thunderbird 2012-11-22
CentOS CESA-2012:1482 firefox 2012-11-22
Scientific Linux SL-thun-20121121 thunderbird 2012-11-21
Oracle ELSA-2012-1483 thunderbird 2012-11-21
Oracle ELSA-2012-1482 firefox 2012-11-21
SUSE SUSE-SU-2012:1592-1 Mozilla Firefox 2012-11-29
openSUSE openSUSE-SU-2012:1586-1 xulrunner 2012-11-28
openSUSE openSUSE-SU-2012:1583-1 firefox 2012-11-28
Mageia MGASA-2012-0343 thunderbird 2012-11-23
Ubuntu USN-1638-2 ubufox 2012-11-21
Ubuntu USN-1636-1 thunderbird 2012-11-21
Slackware SSA:2012-326-03 thunderbird 2012-11-21
Slackware SSA:2012-326-01 seamonkey 2012-11-21
Fedora FEDORA-2012-18683 thunderbird-enigmail 2012-11-22
Fedora FEDORA-2012-18683 thunderbird 2012-11-22
Fedora FEDORA-2012-18931 seamonkey 2012-12-04
openSUSE openSUSE-SU-2012:1585-1 thunderbird 2012-11-28
Mageia MGASA-2012-0342 firefox 2012-11-23
Slackware SSA:2012-326-02 firefox 2012-11-21
Oracle ELSA-2012-1482 firefox 2012-11-21
Fedora FEDORA-2012-18683 xulrunner 2012-11-22
Fedora FEDORA-2012-18683 thunderbird-lightning 2012-11-22
Mandriva MDVSA-2012:173 firefox 2012-11-21
Red Hat RHSA-2012:1483-01 thunderbird 2012-11-20
Fedora FEDORA-2012-18952 seamonkey 2012-12-04
Ubuntu USN-1638-3 firefox 2012-12-03
openSUSE openSUSE-SU-2012:1584-1 seamonkey 2012-11-28
Ubuntu USN-1638-1 firefox 2012-11-21
CentOS CESA-2012:1483 thunderbird 2012-11-22
CentOS CESA-2012:1482 firefox 2012-11-22
Scientific Linux SL-fire-20121121 firefox 2012-11-21
Red Hat RHSA-2012:1482-01 firefox 2012-11-20

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds