Lucene search

K
mozillaMozilla FoundationMFSA2012-05
HistoryJan 31, 2012 - 12:00 a.m.

Frame scripts calling into untrusted objects bypass security checks — Mozilla

2012-01-3100:00:00
Mozilla Foundation
www.mozilla.org
32

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

60.9%

Mozilla security researcher moz_bug_r_a4 reported that frame scripts bypass XPConnect security checks when calling untrusted objects. This allows for cross-site scripting (XSS) attacks through web pages and Firefox extensions. The fix enables the Script Security Manager (SSM) to force security checks on all frame scripts.

Affected configurations

Vulners
Node
mozillafirefoxRange<10
OR
mozillaseamonkeyRange<2.7
OR
mozillathunderbirdRange<10

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

60.9%