CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade seamonkeyUpgrade seamonkey-chatUpgrade seamonkey-mailUpgrade xulrunnerUpgrade thunderbirdUpgrade seamonkey-develUpgrade xulrunner-develUpgrade seamonkey-dom-inspectorUpgrade seamonkey-js-debugger | Dec 1, 2016 | Jun 30, 2011 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/icecat.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey. | Oct 30, 2017 | Jun 30, 2011 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade thunderbirdUpgrade xulrunnerUpgrade firefox | Oct 16, 2024 | Jun 30, 2011 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Nov 19, 2024 | Jun 30, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub