Upstream information
Description
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.NVD CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 790140 SUSE Security Advisories:- openSUSE-SU-2012:1583-1, published Wed, 28 Nov 2012 17:08:34 +0100 (CET)
- openSUSE-SU-2012:1584-1, published Wed, 28 Nov 2012 17:08:53 +0100 (CET)
- openSUSE-SU-2012:1585-1, published Wed, 28 Nov 2012 17:09:11 +0100 (CET)
- openSUSE-SU-2012:1586-1, published Wed, 28 Nov 2012 17:09:28 +0100 (CET)
- openSUSE-SU-2013:0175-1, published Wed, 23 Jan 2013 14:07:31 +0100 (CET)
