Mozilla: Local files or privileged URLs in pages can be opened into new tabs (MFSA 2015-60)
Published Jul 6, 2015
6.8
MEDIUMCVSS 2.0
EPSS 1.81%
Description
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
firefox-0:38.1.0-1.el5_11
Fixed · RHSA-2015:1207
Red Hat Enterprise Linux 6
firefox-0:38.1.0-1.el6_6
Fixed · RHSA-2015:1207
Red Hat Enterprise Linux 7
firefox-0:38.1.0-1.ael7b_1
Fixed · RHSA-2015:1207
Red Hat Enterprise Linux 5
thunderbird
Not affected
Red Hat Enterprise Linux 6
thunderbird
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox-0:38.1.0-1.el5_11 | Fixed | RHSA-2015:1207 |
| Red Hat Enterprise Linux 6 | firefox-0:38.1.0-1.el6_6 | Fixed | RHSA-2015:1207 |
| Red Hat Enterprise Linux 7 | firefox-0:38.1.0-1.ael7b_1 | Fixed | RHSA-2015:1207 |
| Red Hat Enterprise Linux 5 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of thunderbird package, as shipped with Red Hat Enterprise Linux 5, 6 and 7.
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-1207.html vendor-advisoryx_refsource_REDHAT
- http://www.mozilla.org/security/announce/2015/mfsa2015-60.html x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/75541 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1032783 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2656-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2656-2 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-2727 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1163422 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1236950 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-2727
- https://security.gentoo.org/glsa/201512-10 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2015-2727
Change history (0)
No recorded changes yet.