Уязвимость межсайтового скриптинга (XSS) в реализации набора символов HZ-GB-2312 в Mozilla Firefox, Thunderbird и SeaMonkey через некорректную обработку символа тильда (~) возле разделителя блока
Описание
В реализации набора символов HZ-GB-2312 в Mozilla Firefox, Thunderbird и SeaMonkey обнаружена уязвимость, связанная с некорректной обработкой символа тильда (~
) вблизи разделителя блока. Эта уязвимость позволяет злоумышленникам осуществлять межсайтовые скриптинговые атаки (XSS) посредством специально сформированного документа.
Затронутые версии ПО
- Mozilla Firefox версии до 17.0
- Mozilla Firefox ESR 10.x версии до 10.0.11
- Thunderbird версии до 17.0
- Thunderbird ESR 10.x версии до 10.0.11
- SeaMonkey версии до 2.14
Тип уязвимости
Межсайтовый скриптинг (XSS)
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
The HZ-GB-2312 character-set implementation in Mozilla Firefox before ...
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.
EPSS
4.3 Medium
CVSS2