CVE-2012-4208
Publication date 21 November 2012
Last updated 24 July 2024
Ubuntu priority
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
xulrunner-2.0 | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1638-1
- Firefox vulnerabilities
- 21 November 2012
- USN-1636-1
- Thunderbird vulnerabilities
- 21 November 2012