CVE-2012-3973

Published: 29 August 2012

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream
Released (15.0)
seamonkey
Launchpad, Ubuntu, Debian
Upstream Needs triage

thunderbird
Launchpad, Ubuntu, Debian
Upstream Not vulnerable

xulrunner-1.9.2
Launchpad, Ubuntu, Debian
Upstream Needs triage

xulrunner-2.0
Launchpad, Ubuntu, Debian
Upstream Needs triage