XAML injection In thunderbird
Description
A flaw was found in the way documents were loaded via resource URLs in, for example, Mozilla's PDF.js PDF file viewer. An attacker could use this flaw to bypass certain restrictions and under certain conditions even execute arbitrary code with the privileges of the user running Firefox.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:31.6.0-2.el5_11 | ||
rpm rhel6 | 0:31.6.0-2.el6_6 | ||
rpm rhel7 | 0:31.6.0-2.el7_1 | ||
rpm rhel5 | 0:31.6.0-1.el5_11 | ||
rpm rhel6 | 0:31.6.0-1.el6_6 | ||
rpm rhel7 | 0:31.6.0-1.el7_1 | ||
rpm rhel7 | 0:31.6.0-2.el7_1 |
Aliases
1. 2. 3.
References
1. 2.