CVE-2011-3004

Publication date 30 September 2011

Last updated 24 July 2024


Ubuntu priority

The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.

Status

Package Ubuntu Release Status
firefox 11.04 natty
Fixed 7.0.1+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1222-1
    • Firefox vulnerabilities
    • 29 September 2011

Other references