Уязвимость удалённого выполнения JavaScript-кода с привилегиями браузера через некорректное ограничение изменения домашней страницы в Mozilla Firefox, Thunderbird и SeaMonkey
Описание
в Mozilla Firefox, Thunderbird и SeaMonkey обнаружена уязвимость, позволяющая злоумышленникам с удалённой стороны выполнять произвольный JavaScript-код с привилегиями браузера. Это происходит из-за некорректного ограничения на изменение домашней страницы через перетаскивание URL на кнопку "Домашняя страница". Уязвимость может быть использована при помощи URL вида javascript:
, который впоследствии интерпретируется в контексте about:sessionrestore
.
Затронутые версии ПО
- Mozilla Firefox до версии 3.6.28 и с 4.x по 10.0
- Firefox ESR 10.x до 10.0.3
- Thunderbird до версии 3.1.20 и с 5.0 по 10.0
- Thunderbird ESR 10.x до 10.0.3
- SeaMonkey до версии 2.8
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.
EPSS
6.8 Medium
CVSS2