Upstream information
Description
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 790140 SUSE Security Advisories:- openSUSE-SU-2012:1583-1, published Wed, 28 Nov 2012 17:08:34 +0100 (CET)
- openSUSE-SU-2012:1584-1, published Wed, 28 Nov 2012 17:08:53 +0100 (CET)
- openSUSE-SU-2012:1585-1, published Wed, 28 Nov 2012 17:09:11 +0100 (CET)
- openSUSE-SU-2012:1586-1, published Wed, 28 Nov 2012 17:09:28 +0100 (CET)
- openSUSE-SU-2013:0175-1, published Wed, 23 Jan 2013 14:07:31 +0100 (CET)
