Upstream information
Description
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 720264 SUSE Security Advisories:- SUSE-SU-2011:1256-1, published Thu, 17 Nov 2011 23:08:23 +0100 (CET)
- SUSE-SU-2011:1256-2, published Fri, 18 Nov 2011 22:08:26 +0100 (CET)
- openSUSE-SU-2011:1077-1, published Thu, 29 Sep 2011 15:08:19 +0200 (CEST)
- openSUSE-SU-2011:1290-1, published Thu, 1 Dec 2011 15:08:20 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.3 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
| |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 SUSE Linux Enterprise Server 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| Builds ZYPP Patch Nr: 7842 |
