Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-0958
HistoryNov 06, 2012 - 12:00 a.m.

CVE-2012-0958

2012-11-0600:00:00
ubuntu.com
ubuntu.com
8

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.2%

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for
Firefox exposes the toDataURL function in an API call, which allows remote
attackers to bypass the Same Origin Policy and obtain sensitive information
via a crafted webpage.

Bugs

Notes

Author Note
mdeslaur security fix breaks ABI, and breaks some of the existing webapps. See bug for more information.
OSVersionArchitecturePackageVersionFilename
ubuntu12.10noarchunity-firefox-extension< 2.4.1-0ubuntu1.2UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.2%