FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1840

This CVE name corresponds to:

Entered Topic
2009-06-12 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1840
Phase Assigned(20090529)

Description

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-31.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=477979
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=503582
DEBIAN DSA-1820
FEDORA FEDORA-2009-6366
FEDORA FEDORA-2009-6411
MANDRIVA MDVSA-2009:141
REDHAT RHSA-2009:1095
SLACKWARE SSA:2009-167-01
SUNALERT 264308
BID 35326
OSVDB 55158
OVAL oval:org.mitre.oval:def:9448
SECTRACK 1022379
SECUNIA 35331
SECUNIA 35431
SECUNIA 35439
SECUNIA 35440
SECUNIA 35468
SECUNIA 35415
VUPEN ADV-2009-1572
XF firefox-xul-security-bypass(51076)