You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2012-47

Mozilla Foundation Security Advisory 2012-47

Title: Improper filtering of javascript in HTML feed-view
Impact: High
Announced: July 17, 2012
Reporter: Mario Heiderich
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 14
  Firefox ESR 10.0.6
  Thunderbird 14
  Thunderbird ESR 10.0.6
  SeaMonkey 2.11

Description

Security researcher Mario Heiderich reported that javascript could be executed in the HTML feed-view using <embed> tag within the RSS <description>. This problem is due to <embed> tags not being filtered out during parsing and can lead to a potential cross-site scripting (XSS) attack. The flaw existed in a parser utility class and could affect other parts of the browser or add-ons which rely on that class to sanitize untrusted input.

References