Lucene search

K
mozillaMozilla FoundationMFSA2011-08
HistoryMar 01, 2011 - 12:00 a.m.

ParanoidFragmentSink allows javascript: URLs in chrome documents — Mozilla

2011-03-0100:00:00
Mozilla Foundation
www.mozilla.org
13

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.023

Percentile

89.8%

Security researcher Roberto Suggi Liverani reported that ParanoidFragmentSink, a class used to sanitize potentially unsafe HTML for display, allows javascript: URLs and other inline JavaScript when the embedding document is a chrome document. While there are no unsafe uses of this class in any released products, extension code could have potentially used it in an unsafe manner.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.5.17
OR
mozillafirefoxRange<3.6.14
OR
mozillaseamonkeyRange<2.0.12
OR
mozillathunderbirdRange<3.1.8
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.023

Percentile

89.8%