Upstream information
Description
The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 712224 SUSE Security Advisories:- SUSE-SA:2011:037, published Mon, 29 Aug 2011 12:00:00 +0000
- openSUSE-SU-2011:0957-1, published Fri, 26 Aug 2011 20:08:16 +0200 (CEST)
- openSUSE-SU-2011:0957-2, published Mon, 29 Aug 2011 21:08:18 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
|
