CVE-2011-3666: Medium severity firefox vulnerability
Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3666?
CVE-2011-3666 has a medium severity rating, allowing user-assisted remote attackers to bypass access restrictions.
How do I fix CVE-2011-3666?
To fix CVE-2011-3666, it is recommended to update affected versions of Mozilla Firefox and Thunderbird to the latest versions available.
What versions are affected by CVE-2011-3666?
CVE-2011-3666 affects Mozilla Firefox versions before 3.6.25 and Thunderbird versions before 3.1.17 on Mac OS X.
Can I still use the affected versions of Firefox and Thunderbird safely with CVE-2011-3666?
Using affected versions is not safe as CVE-2011-3666 can be exploited by attackers if a user interacts with a malicious .jar file.
Is there any workaround for CVE-2011-3666 until I can update?
There is no reliable workaround for CVE-2011-3666; updating to a secure version is the only recommendation.