Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2011-3001

Published: 30 September 2011

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
hardy Ignored
(uses system xulrunner)
lucid Not vulnerable

maverick Not vulnerable
(3.6.23+build1+nobinonly-0ubuntu0.10.10.1)
natty
Released (7.0.1+build1+nobinonly-0ubuntu0.11.04.1)
upstream
Released (7.0)