USN-728-2 -- firefox vulnerabilitiesID: oval:org.secpod.oval:def:700385 | Date: (C)2011-05-13 (M)2021-06-02 |
Class: PATCH | Family: unix |
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Georgi Guninski discovered a flaw when Firefox performed a cross-domain redirect. An attacker could bypass the same-origin policy in Firefox by utilizing nsIRDFService and steal private data from users authenticated to the redirected website