CVE-2011-3647: Input Validation
The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3647?
CVE-2011-3647 has a moderate severity rating due to its potential to allow remote attackers to gain privileges.
How do I fix CVE-2011-3647?
To fix CVE-2011-3647, upgrade Mozilla Firefox to version 3.6.24 or later and Thunderbird to version 3.1.6 or later.
What kind of attacks can exploit CVE-2011-3647?
CVE-2011-3647 can be exploited through crafted websites that misuse the loadSubScript method in add-ons.
Which versions of Firefox are affected by CVE-2011-3647?
CVE-2011-3647 affects Firefox versions prior to 3.6.24.
Which versions of Thunderbird are affected by CVE-2011-3647?
CVE-2011-3647 affects Thunderbird versions prior to 3.1.6.