Mozilla Foundation Security Advisory 2010-79
Java security bypass from LiveConnect loaded via data: URL meta refresh
- Announced
- December 9, 2010
- Reporter
- Gregory Fleischer
- Impact
- Critical
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 3.5.16
- Firefox 3.6.13
- SeaMonkey 2.0.11
Description
Security researcher Gregory Fleischer reported
that when a Java LiveConnect script was loaded via
a data:
URL which redirects via a meta refresh, then the
resulting plugin object was created with the wrong security principal
and thus received elevated privileges such as the abilities to read
local files, launch processes, and create network connections.