Novell Home

CVE-2011-3004

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2011-3004 at MITRE

Description

The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Novell/SUSE information

Novell Bugzilla entry: 720264

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 11.4
  • MozillaFirefox >= 7.0-1.2.1
  • MozillaFirefox-branding-upstream >= 7.0-1.2.1
  • MozillaFirefox-buildsymbols >= 7.0-1.2.1
  • MozillaFirefox-devel >= 7.0-1.2.1
  • MozillaFirefox-translations-common >= 7.0-1.2.1
  • MozillaFirefox-translations-other >= 7.0-1.2.1
openSUSE 11.3
  • seamonkey-debuginfo >= 2.4-1.2.1
  • seamonkey-debugsource >= 2.4-1.2.1
openSUSE 11.3
openSUSE 11.4
  • seamonkey >= 2.4-1.2.1
  • seamonkey-dom-inspector >= 2.4-1.2.1
  • seamonkey-irc >= 2.4-1.2.1
  • seamonkey-translations-common >= 2.4-1.2.1
  • seamonkey-translations-other >= 2.4-1.2.1
  • seamonkey-venkman >= 2.4-1.2.1

© 2014 Novell