CVE-2009-1840: Critical severity Mozilla SeaMonkey vulnerability
Mozilla add-on developer and community member Wladimir Palant reported that two key security checks are not being called when loading XUL scripts. The checks which are skipped are intended to verify that content loading policies will not be violated by loading a XUL script. Mozilla code relying on the content policies for security, such as privileged add-ons, could potentially be exploited to run JavaScript with elevated privileges.
Other sources
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1840?
CVE-2009-1840 is classified as a moderate severity vulnerability.
How do I fix CVE-2009-1840?
To fix CVE-2009-1840, you should update your Mozilla Firefox or SeaMonkey to the latest version that addresses this vulnerability.
Which software is affected by CVE-2009-1840?
CVE-2009-1840 affects several versions of Mozilla Firefox (3.0.0 to 3.0.10) and Mozilla SeaMonkey.
What is the nature of the vulnerability described in CVE-2009-1840?
CVE-2009-1840 involves skipping crucial security checks when loading XUL scripts, potentially violating content loading policies.
Is CVE-2009-1840 still a threat today?
While CVE-2009-1840 is a historical vulnerability, using outdated software can put systems at risk, so it is best to update to the latest versions to mitigate any potential risks.