[Forgot Password]
Login  Register Subscribe

23631

 
 

117687

 
 

98218

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: Wrong principal used for validating URI for some Javascript components - mfsa2013-72

ID: oval:org.secpod.oval:def:16335Date: (C)2013-12-30   (M)2017-11-17
Class: PATCHFamily: macos




Security researcher Cody Crews reported that some Javascript components will perform checks against the wrong uniform resource identifier (URI) before performing security sensitive actions. This will return an incorrect location for the originator of the call. This could be used to bypass same-origin policy, allowing for cross-site scripting (XSS) or the installation of malicious add-ons from third-party pages.

Platform:
Apple Mac OS X 10.8
Apple Mac OS X 10.9
Apple Mac OS X 10.10
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X Server 10.8
Apple Mac OS X Server 10.9
Apple Mac OS X Server 10.10
Apple Mac OS X Server 10.11
Apple Mac OS X Server 10.12
Product:
Mozilla Firefox
Mozilla Thunderbird ESR
Mozilla SeaMonkey
Mozilla Thunderbird
Mozilla Firefox ESR
Reference:
MFSA 2013-72
CVE-2013-1713
CVE    1
CVE-2013-1713
CPE    183
cpe:/a:mozilla:firefox:20.0.1
cpe:/a:mozilla:firefox:19.0.1
cpe:/a:mozilla:firefox:19.0.2
cpe:/a:mozilla:firefox:22.0
...

© 2013 SecPod Technologies