Mozilla Foundation Security Advisory 2012-101
Improper character decoding in HZ-GB-2312 charset
- Announced
- November 20, 2012
- Reporter
- Masato Kinugawa
- Impact
- High
- Products
- Firefox, Firefox ESR, SeaMonkey, Thunderbird, Thunderbird ESR
- Fixed in
-
- Firefox 17
- Firefox ESR 10.0.11
- SeaMonkey 2.14
- Thunderbird 17
- Thunderbird ESR 10.0.11
Description
Security researcher Masato Kinugawa found when HZ-GB-2312 charset encoding is used for text, the "~" character will destroy another character near the chunk delimiter. This can lead to a cross-site scripting (XSS) attack in pages encoded in HZ-GB-2312.