CVE-2011-3001

Publication date 30 September 2011

Last updated 24 July 2024


Ubuntu priority

Description

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

Status

Package Ubuntu Release Status
firefox 11.04 natty
Fixed 7.0.1+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1222-1
    • Firefox vulnerabilities
    • 29 September 2011

Other references