PT-2007-5079 · Mozilla+1 · Firefox+3

Published

2007-08-08

·

Updated

2018-10-15

·

CVE-2007-3844

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions 2.0.0.5 and earlier Thunderbird versions 2.0.0.5 and earlier, and versions prior to 1.5.0.13 SeaMonkey version 1.1.3
Description: The issue allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges. This is achieved via an addon that inserts a javascript: or data: link into an about:blank document loaded by chrome. The document can be loaded using the window.open function or a content.location assignment.
Recommendations: For Mozilla Firefox versions 2.0.0.5 and earlier, update to a version that fixes the regression issue. For Thunderbird versions 2.0.0.5 and earlier, and versions prior to 1.5.0.13, update to a version that fixes the regression issue. For SeaMonkey version 1.1.3, update to a version that fixes the regression issue. As a temporary workaround, consider disabling the use of addons that insert javascript: or data: links into documents loaded by chrome until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3844
DSA-1344-1
DSA-1345-1
DSA-1346-1
DSA-1391-1
DTSA-51-1
DTSA-52-1
DTSA-53-1
DTSA-71-1
HPSBUX02153
RHSA-2007:0979
RHSA-2007:0980
RHSA-2007:0981
RHSA-2007_0979
RHSA-2007_0980
RHSA-2007_0981

Affected Products

Firefox
Red Hat
Seamonkey
Thunderbird