Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:FIREFOX-XDOMAIN-INFODISC

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Mozilla Firefox Cross Domain Information Disclosure

Release Date

2012/11/07

Update Number

2201

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Mozilla Firefox Cross Domain Information Disclosure


This signature detects attempts to exploit a known vulnerability against Mozilla Firefox. A successful attack can lead to disclosure of sensitive information that an attacker could leverage further to launch additional attacks.

Extended Description

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.

Affected Products

  • mozilla firefox 16.0
  • mozilla seamonkey 2.13
  • mozilla thunderbird 16.0

References

  • BugTraq: 56154
  • CVE: CVE-2012-4192
  • URL: http://www.mozilla.org/security/announce/2012/mfsa2012-89.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out