Lucene search

K
mozillaMozilla FoundationMFSA2012-76
HistoryOct 09, 2012 - 12:00 a.m.

Continued access to initial origin after setting document.domain — Mozilla

2012-10-0900:00:00
Mozilla Foundation
www.mozilla.org
22

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.6%

Security researcher Collin Jackson reported a violation of the HTML5 specifications for document.domain behavior. Specified behavior requires pages to only have access to windows in a new document.domain but the observed violation allowed pages to retain access to windows from the page’s initial origin in addition to the new document.domain. This could potentially lead to cross-site scripting (XSS) attacks.

Affected configurations

Vulners
Node
mozillafirefoxRange<16
OR
mozillaseamonkeyRange<2.13
OR
mozillathunderbirdRange<16
CPENameOperatorVersion
firefoxlt16
seamonkeylt2.13
thunderbirdlt16

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.6%