Bug 1277342 (CVE-2015-7187) - CVE-2015-7187 Mozilla: disabling scripts in Add-on SDK panels has no effect (MFSA 2015-121)
Summary: CVE-2015-7187 Mozilla: disabling scripts in Add-on SDK panels has no effect (...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2015-7187
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1275590
TreeView+ depends on / blocked
 
Reported: 2015-11-03 05:48 UTC by Huzaifa S. Sidhpurwala
Modified: 2023-05-12 10:54 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-11-04 04:57:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Huzaifa S. Sidhpurwala 2015-11-03 05:48:29 UTC
Add-on authors Jason Hamilton and Peter Arremann with AMO editor Sylvain Giroux reported a vulnerability when a panel is created using the Add-on SDK in a browser extension. Defining a panel with script: false is supposed to disable script execution but it was found that inline script would still execute. This flaw allows for the potential execution of script content in an extension when it was been explicitly disallowed.

The potential impact of this flaw would depend on whether the add-on was relying on script: false as a security mechanism and from location the panel content was loaded. No add-ons served from addons.mozilla.org are vulnerable to this flaw but add-ons installed from third party sites may be.


External Reference:

https://www.mozilla.org/security/announce/2015/mfsa2015-121.html


Acknowledgements:

Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Jason Hamilton as the original reporter.

Statement:

This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.


Note You need to log in before you can comment on or make changes to this bug.