PT-2011-4237 · Mozilla+1 · Thunderbird+3

Boris Zbarsky

+1

·

Published

2011-09-27

·

Updated

2017-09-19

·

CVE-2011-2999

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.6.23 Mozilla Firefox versions 4.x through 5 Thunderbird versions prior to 6.0 SeaMonkey versions prior to 2.3
Description The issue arises from improper handling of "location" as the name of a frame, allowing remote attackers to bypass the Same Origin Policy via a crafted web site.
Recommendations For Mozilla Firefox versions prior to 3.6.23, update to version 3.6.23 or later. For Mozilla Firefox versions 4.x through 5, update to a version later than 5. For Thunderbird versions prior to 6.0, update to version 6.0 or later. For SeaMonkey versions prior to 2.3, update to version 2.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2999
DSA-2312-1
DSA-2313-1
DSA-2317-1
RHSA-2011:1341
RHSA-2011:1342
RHSA-2011:1343
RHSA-2011:1344
RHSA-2011_1341
RHSA-2011_1342
RHSA-2011_1343
RHSA-2011_1344

Affected Products

Firefox
Red Hat
Seamonkey
Thunderbird