Mozilla Foundation Security Advisory 2007-25
XPCNativeWrapper pollution
- Announced
- July 17, 2007
- Reporter
- shutdown and moz_bug_r_a4
- Impact
- Moderate
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 2.0.0.5
- SeaMonkey 1.1.3
Description
Mozilla security researchers shutdown and moz_bug_r_a4 reported two separate ways to modify an XPCNativeWrapper such that subsequent access by the browser would result in executing user-supplied code.