Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:24320
HistoryJul 24, 2010 - 12:00 a.m.

Mozilla Foundation Security Advisory 2010-47

2010-07-2400:00:00
vulners.com
57

EPSS

0.003

Percentile

68.4%

Mozilla Foundation Security Advisory 2010-47

Title: Cross-origin data leakage from script filename in error messages
Impact: Moderate
Announced: July 20, 2010
Reporter: Soroush Dalili
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 3.6.7
Firefox 3.5.11
Thunderbird 3.1.1
Thunderbird 3.0.6
SeaMonkey 2.0.6
Description

Security researcher Soroush Dalili reported that potentially sensitive URL parameters could be leaked across domains upon script errors when the script filename and line number is included in the error message.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=568564
* CVE-2010-2754