Signed scripts requesting enhanced abilities could construct the request in a way that led to a confusing grant dialog, possibly fooling the user into thinking the privilege requested was inconsequential while actually obtaining explicit permission to run and install software. Workaround: Never grant enhanced abilities of any kind to untrusted web pages. See http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3 for more information.
This issue is going to be RHSA-2004:486.
This issue doesn't affect our mozilla.