CVE-2012-4193
Published: 11 October 2012
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.
Notes
Author | Note |
---|---|
jdstrand | xulrunner-1.9.2 unmaintained upstream (see README.mozilla for details) |
micahg | this CVE is for the pre-16 fix |
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Not vulnerable
(16.0+build1-0ubuntu0.10.04.1)
|
|
natty |
Not vulnerable
(16.0+build1-0ubuntu0.11.04.1)
|
|
oneiric |
Not vulnerable
(16.0+build1-0ubuntu0.11.10.1)
|
|
precise |
Not vulnerable
(16.0+build1-0ubuntu0.12.04.1)
|
|
quantal |
Not vulnerable
(16.0+build1-0ubuntu1)
|
|
raring |
Not vulnerable
(16.0+build1-0ubuntu1)
|
|
saucy |
Not vulnerable
(16.0+build1-0ubuntu1)
|
|
upstream |
Released
(16.0.1)
|
|
seamonkey Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
natty |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Released
(2.13.1)
|
|
thunderbird Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(16.0.1+build1-0ubuntu0.10.04.1)
|
|
natty |
Released
(16.0.1+build1-0ubuntu0.11.04.1)
|
|
oneiric |
Released
(16.0.1+build1-0ubuntu0.11.10.1)
|
|
precise |
Released
(16.0.1+build1-0ubuntu0.12.04.1)
|
|
quantal |
Released
(16.0.1+build1-0ubuntu1)
|
|
raring |
Released
(16.0.1+build1-0ubuntu1)
|
|
saucy |
Released
(16.0.1+build1-0ubuntu1)
|
|
upstream |
Released
(16.0.1)
|
|
xulrunner-1.9.2 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
natty |
Ignored
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-2.0 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
natty |
Ignored
(end of life)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
|