Back

LOW

Multiple flaws in Firefox 12 which do not affect firefox 10.0.4 ESR

Published Apr 25, 2012

Description

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

Affected products

Remediation

Red Hat statement

Not Vulnerable. These issues do not affect the versions of firefox and thunderbird package, as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 25, 2012
Updated Aug 6, 2024
Reserved Jan 9, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Apr 24, 2012