Lack of data validation In firefox
Description
Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:3.6.14-4.el5_6 | ||
rpm rhel5 | 0:2.0.0.24-14.el5_6 | ||
rpm rhel6 | 0:1.9.2.14-3.el6_0 | ||
rpm rhel6 | 0:3.6.14-4.el6_0 | ||
rpm rhel5 | 0:1.9.2.14-4.el5_6 |
Aliases
1. 2. 3.