CVE-2012-4192
Published: 10 October 2012
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
Notes
Author | Note |
---|---|
jdstrand | Mozilla plans push out on 2012-10-11. |
micahg | this CVE was for the 16 regression |
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(16.0.1+build1-0ubuntu0.10.04.1)
|
|
natty |
Released
(16.0.1+build1-0ubuntu0.11.04.1)
|
|
oneiric |
Released
(16.0.1+build1-0ubuntu0.11.10.1)
|
|
precise |
Released
(16.0.1+build1-0ubuntu0.12.04.1)
|
|
upstream |
Released
(16.0.1)
|
|
thunderbird Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Not vulnerable
(15.0.1+build1-0ubuntu0.10.04.1)
|
|
natty |
Not vulnerable
(15.0.1+build1-0ubuntu0.11.04.1)
|
|
oneiric |
Not vulnerable
(15.0.1+build1-0ubuntu0.11.10.1)
|
|
precise |
Not vulnerable
(15.0.1+build1-0ubuntu0.12.04.1)
|
|
upstream |
Released
(16.0.1)
|