Fedora Account System
Red Hat Associate
Red Hat Customer
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. External Reference: https://www.mozilla.org/security/announce/2016/mfsa2016-89.html Acknowledgements: Name: the Mozilla project Upstream: Kris Maglione Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.