Skip to main content

Mozilla Firefox / Thunderbird JAR File Handling Vulnerability

Last Update Date: 23 Dec 2011 10:22 Release Date: 23 Dec 2011 5819 Views

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability has been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to compromise a user's system.

A malicious JAR file could be downloaded and executed if a user is convinced into holding down the "Enter" key via e.g. a malicious game.

NOTE: This only affects the Mac OS X version.


Impact

  • Remote Code Execution

System / Technologies affected

  • Mozilla Firefox 3.6.x for Mac OS X
  • Mozilla Thunderbird 3.1.x for Mac OS X

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to Firefox version 3.6.25 or Thunderbird 3.1.17.

Vulnerability Identifier


Source


Related Link