CVE-2012-1945: Infoleak
Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1945?
CVE-2012-1945 is classified as a medium severity vulnerability due to the potential for local users to gain sensitive information.
How do I fix CVE-2012-1945?
To fix CVE-2012-1945, update your Mozilla Firefox, Thunderbird, or SeaMonkey installation to a version that is no longer affected by this vulnerability.
What versions are affected by CVE-2012-1945?
CVE-2012-1945 affects Mozilla Firefox versions 4.x through 12.0, Thunderbird versions 5.0 through 12.0, and various versions of SeaMonkey.
What type of attack does CVE-2012-1945 facilitate?
CVE-2012-1945 allows local attackers to exploit the vulnerability to access sensitive information through crafted HTML documents.
Is CVE-2012-1945 still exploitable in recent software versions?
No, CVE-2012-1945 is not exploitable in versions of Mozilla Firefox, Thunderbird, and SeaMonkey that have been updated beyond the affected versions.