Mozilla: Spoofing and script injection through location.hash (MFSA 2012-84)
Published Oct 10, 2012
4.3
MEDIUMCVSS 2.0
EPSS 2.51%
Description
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and history navigation that triggers the loading of a URL into the history object.
Affected products
No data.
Configuration 2
- < 10.0.8
Configuration 4
- < 16.0
Configuration 6
- 10.04
- 11.04
- 11.10
- 12.04
- 5.0
- 6.0
- 6.3
- 5.0
- 6.0
- 5.0
- 6.0
Configuration 7
- 10
- 11
- 10
- 10
- 11
- 11
No data.
Red Hat Enterprise Linux 5
firefox-0:10.0.8-1.el5_8
Fixed · RHSA-2012:1350
Red Hat Enterprise Linux 5
thunderbird-0:10.0.8-1.el5_8
Fixed · RHSA-2012:1351
Red Hat Enterprise Linux 5
xulrunner-0:10.0.8-1.el5_8
Fixed · RHSA-2012:1350
Red Hat Enterprise Linux 6
firefox-0:10.0.8-1.el6_3
Fixed · RHSA-2012:1350
Red Hat Enterprise Linux 6
thunderbird-0:10.0.8-1.el6_3
Fixed · RHSA-2012:1351
Red Hat Enterprise Linux 6
xulrunner-0:10.0.8-1.el6_3
Fixed · RHSA-2012:1350
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox-0:10.0.8-1.el5_8 | Fixed | RHSA-2012:1350 |
| Red Hat Enterprise Linux 5 | thunderbird-0:10.0.8-1.el5_8 | Fixed | RHSA-2012:1351 |
| Red Hat Enterprise Linux 5 | xulrunner-0:10.0.8-1.el5_8 | Fixed | RHSA-2012:1350 |
| Red Hat Enterprise Linux 6 | firefox-0:10.0.8-1.el6_3 | Fixed | RHSA-2012:1350 |
| Red Hat Enterprise Linux 6 | thunderbird-0:10.0.8-1.el6_3 | Fixed | RHSA-2012:1351 |
| Red Hat Enterprise Linux 6 | xulrunner-0:10.0.8-1.el6_3 | Fixed | RHSA-2012:1350 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1351.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/50856 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/50892 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/50904 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/50935 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/50936 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/50984 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/55318 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:163 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mozilla.org/security/announce/2012/mfsa2012-84.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/56128 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1611-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2012-3992 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=775009 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=863624 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2012-3992
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16987 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2012-3992
Change history (0)
No recorded changes yet.