Title: Mozilla Multiple Product IPv6 XMLHttpRequest / WebSocket Handling Same Origin Policy Bypass
Info
Disclosure
Apr 24, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Apr 24, 2012
Description
Multiple Mozilla products contain a flaw that may allow an attacker to bypass the same origin policy when handling XMLHttpRequest and WebSocket via a IPv6 address. No further details have been provided.
Classification
Location:
Remote / Network Access,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade Firefox and Thunderbird to version 12.0 or higher and SeaMonkey to version 2.9 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.