CVE-2012-4208: Infoleak
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4208?
CVE-2012-4208 is rated as a moderate severity vulnerability.
How do I fix CVE-2012-4208?
To fix CVE-2012-4208, update your Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version available.
Who is affected by CVE-2012-4208?
CVE-2012-4208 affects Mozilla Firefox versions before 17.0, Thunderbird versions before 17.0, and SeaMonkey versions before 2.14.
What type of vulnerability is CVE-2012-4208?
CVE-2012-4208 is a DOM property filtering bypass vulnerability.
What can a remote attacker do using CVE-2012-4208?
A remote attacker can exploit CVE-2012-4208 to bypass chrome-only restrictions on reading DOM object properties.