CVE-2012-0450: Low severity firefox vulnerability
Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0450?
CVE-2012-0450 is classified as a moderate severity vulnerability due to the weak permissions set on sensitive files.
How do I fix CVE-2012-0450?
To remediate CVE-2012-0450, ensure that Firefox Recovery Key.html has proper access controls to restrict unauthorized access.
Which software versions are affected by CVE-2012-0450?
CVE-2012-0450 affects Mozilla Firefox versions 4.x to 9.0 and SeaMonkey versions prior to 2.7 on Linux and Mac OS X.
Could CVE-2012-0450 allow local users to exploit sensitive data?
Yes, CVE-2012-0450 allows local users to potentially read a Firefox Sync key due to weak file permissions.
Is there a patch available for CVE-2012-0450?
Yes, users are advised to update to the latest version of Firefox or SeaMonkey to address the vulnerability associated with CVE-2012-0450.