First published: Wed Nov 21 2012(Updated: )
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <17.0 | |
Mozilla SeaMonkey | <2.14 | |
Thunderbird | <17.0 | |
openSUSE | =11.4 | |
openSUSE | =12.1 | |
openSUSE | =12.2 | |
SUSE Linux Enterprise Desktop | =10-sp4 | |
SUSE Linux Enterprise Desktop | =11-sp2 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Software Development Kit | =10-sp4 | |
SUSE Linux Enterprise Software Development Kit | =11-sp2 | |
Ubuntu | =10.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4208 is rated as a moderate severity vulnerability.
To fix CVE-2012-4208, update your Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version available.
CVE-2012-4208 affects Mozilla Firefox versions before 17.0, Thunderbird versions before 17.0, and SeaMonkey versions before 2.14.
CVE-2012-4208 is a DOM property filtering bypass vulnerability.
A remote attacker can exploit CVE-2012-4208 to bypass chrome-only restrictions on reading DOM object properties.