Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
References
Link | Resource |
---|---|
http://www.mozilla.org/security/announce/2012/mfsa2012-69.html | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=768568 | Issue Tracking Vendor Advisory |
http://www.ubuntu.com/usn/USN-1548-2 | Third Party Advisory |
http://www.ubuntu.com/usn/USN-1548-1 | Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.html | Mailing List Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2012-1210.html | Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.html | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/55313 | Third Party Advisory VDB Entry |
http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf | Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16060 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2012-08-29 03:56
Updated : 2020-08-26 13:39
NVD link : CVE-2012-3976
Mitre link : CVE-2012-3976
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_workstation
- enterprise_linux_server
- enterprise_linux_server_eus
- enterprise_linux_eus
mozilla
- firefox_esr
- firefox
- seamonkey
suse
- linux_enterprise_desktop
- linux_enterprise_software_development_kit
- linux_enterprise_server
canonical
- ubuntu_linux
opensuse
- opensuse