Lack of data validation In xulrunner
Description
CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:3.6.18-1.el5_6 | ||
rpm rhel6 | 0:3.6.18-1.el6_1 | ||
rpm rhel5 | 0:2.0.0.24-18.el5_6 | ||
rpm rhel6 | 0:3.1.11-2.el6_1 | ||
rpm rhel5 | 0:1.9.2.18-2.el5_6 | ||
rpm rhel6 | 0:1.9.2.18-2.el6_1 |
Aliases
1. 2. 3.