Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2180-1 | iceape security update |
Debian DSA |
DSA-2186-1 | iceweasel security update |
Debian DSA |
DSA-2187-1 | icedove security update |
EUVD |
EUVD-2011-0085 | Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site. |
Ubuntu USN |
USN-1049-1 | Firefox and Xulrunner vulnerabilities |
Ubuntu USN |
USN-1123-1 | Xulrunner vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T21:43:14.229Z
Reserved: 2010-12-21T00:00:00
Link: CVE-2011-0059
No data.
Status : Deferred
Published: 2011-03-02T20:00:01.597
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0059
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN