CVE-2012-4192

Publication date 10 October 2012

Last updated 24 July 2024


Ubuntu priority

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 12.04 LTS precise
Fixed 16.0.1+build1-0ubuntu0.12.04.1
11.10 oneiric
Fixed 16.0.1+build1-0ubuntu0.11.10.1
11.04 natty
Fixed 16.0.1+build1-0ubuntu0.11.04.1
10.04 LTS lucid
Fixed 16.0.1+build1-0ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life
thunderbird 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


jdstrand

Mozilla plans push out on 2012-10-11.


micahg

this CVE was for the 16 regression

References

Related Ubuntu Security Notices (USN)

    • USN-1608-1
    • Firefox vulnerabilities
    • 11 October 2012
    • USN-1611-1
    • Thunderbird vulnerabilities
    • 12 October 2012

Other references