CVE-2009-1841: Code Injection
js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
Other sources
Mozilla security researcher mozbugra4 reported a series of vulnerabilities which allow scripts from page content to run with elevated privileges. Using these vulnerabilities, an attacker could cause a chrome privileged object, such as the browser sidebar or the FeedWriter, to interact with web content in such a way that attacker controlled code may be executed with the object's chrome privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1841?
CVE-2009-1841 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2009-1841?
To mitigate CVE-2009-1841, update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that are unaffected by this vulnerability.
What versions are affected by CVE-2009-1841?
CVE-2009-1841 affects Mozilla Firefox versions earlier than 3.0.11, Thunderbird versions earlier than 2.0.0.22, and SeaMonkey versions earlier than 1.1.17.
Can CVE-2009-1841 allow attackers to execute arbitrary code?
Yes, CVE-2009-1841 allows remote attackers to execute arbitrary web script with the privileges of a chrome object.
Is there a workaround for CVE-2009-1841 until I can update?
Disabling script execution in your browser settings may act as a temporary workaround for CVE-2009-1841.