Improper authorization control for web services In firefox
Description
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 0:31.6.0-2.el7_1 | ||
rpm rhel7 | 0:31.6.0-1.el7_1 | ||
rpm rhel7 | 0:31.6.0-2.el7_1 | ||
rpm rhel5 | 0:31.6.0-2.el5_11 | ||
rpm rhel6 | 0:31.6.0-2.el6_6 | ||
rpm rhel5 | 0:31.6.0-1.el5_11 | ||
rpm rhel6 | 0:31.6.0-1.el6_6 |
Aliases
1. 2. 3.