Upstream information
Description
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.NVD CVSS v2 Base Score: 2.6 (AV:N/AC:H/Au:N/C:P/I:N/A:N)
Novell/SUSE information
No Novell Bugzilla entries cross referenced. SUSE Security Advisories:- SUSE-SU-2011:1256-1, published Thu, 17 Nov 2011 23:08:23 +0100 (CET)
- SUSE-SU-2011:1256-2, published Fri, 18 Nov 2011 22:08:26 +0100 (CET)
- openSUSE-SU-2011:1290-1, published Thu, 1 Dec 2011 15:08:20 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 SUSE Linux Enterprise Server 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| Builds ZYPP Patch Nr: 7842 |
