Back

HIGH

Mozilla: Escalation of privilege through about:newtab (MFSA 2012-60)

Published Aug 29, 2012

Description

Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers creation of a new tab and then a new window.

Affected products

Remediation

Red Hat statement

Not Vulnerable. This issue does not affect the version of Firefox and Thunderbird as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 29, 2012
Updated Aug 6, 2024
Reserved Jul 11, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Aug 28, 2012