Lack of data validation - Path Traversal In xulrunner
Description
Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:1.9.2.17-3.el5_6 | ||
rpm rhel6 | 0:1.9.2.17-4.el6_0 | ||
rpm rhel6 | 0:3.1.10-1.el6_0 | ||
rpm rhel6 | 0:3.6.17-1.el6_0 | ||
rpm rhel5 | 0:3.6.17-1.el5_6 |
Aliases
1. 2. 3.