HTTP: Mozilla Firefox Cross Domain Information Disclosure

This signature detects attempts to exploit a known vulnerability against Mozilla Firefox. A successful attack can lead to disclosure of sensitive information that an attacker could leverage further to launch additional attacks.

Extended Description

Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.

Affected Products

Mozilla thunderbird

Short Name
HTTP:FIREFOX-XDOMAIN-INFODISC
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2012-4192 Cross Disclosure Domain Firefox Information Mozilla bid:56154
Release Date
11/07/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Mozilla

CVSS Score

4.3

Found a potential security threat?