Upstream information
Description
Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 712224 SUSE Security Advisories:- SUSE-SA:2011:037, published Mon, 29 Aug 2011 12:00:00 +0000
- openSUSE-SU-2011:0957-1, published Fri, 26 Aug 2011 20:08:16 +0200 (CEST)
- openSUSE-SU-2011:0957-2, published Mon, 29 Aug 2011 21:08:18 +0200 (CEST)
- openSUSE-SU-2012:0567-1, published Fri, 27 Apr 2012 15:08:15 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
|
