Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2011-28

Non-whitelisted site can trigger xpinstall

Announced
June 21, 2011
Reporter
moz_bug_r_a4
Impact
Low
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 5
  • SeaMonkey 2.2

Description

Mozilla security researcher moz_bug_r_a4 reported that it was possible for a non-whitelisted site to trigger an install dialog for add-ons and themes.

This vulnerability was introduced in the browser engine used by Firefox 4 and SeaMonkey 2.1; it does not affect earlier versions.

References