CVE-2012-4205 Information
Description
Mozilla Firefox before 17.0 Thunderbird before 17.0 and SeaMonkey before 2.14 assign the system principal rather than the sandbox principal to XMLHttpRequest objects created in sandboxes which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.
Reference
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00021.html http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00022.html http://lists.opensuse.org/opensuse-updates/2012-11/msg00090.html http://lists.opensuse.org/opensuse-updates/2012-11/msg00092.html http://lists.opensuse.org/opensuse-updates/2012-11/msg00093.html http://secunia.com/advisories/51369 http://secunia.com/advisories/51370 http://secunia.com/advisories/51381 http://secunia.com/advisories/51434 http://secunia.com/advisories/51439 http://secunia.com/advisories/51440 http://www.mozilla.org/security/announce/2012/mfsa2012-97.html http://www.securityfocus.com/bid/56621 http://www.ubuntu.com/usn/USN-1636-1 http://www.ubuntu.com/usn/USN-1638-1 http://www.ubuntu.com/usn/USN-1638-2 http://www.ubuntu.com/usn/USN-1638-3 https://bugzilla.mozilla.org/show_bug.cgi?id=779821 https://exchange.xforce.ibmcloud.com/vulnerabilities/80175 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A16965
Share on: