Red Hat Bugzilla – Bug 394261
CVE-2007-5960 Mozilla Cross-site Request Forgery flaw
Last modified: 2016-03-04 07:49:34 EST
A race condition exists when setting the window.location property on a web page. This flaw could allow a page to set an arbitrary Referer header, which may lead to a Cross-site Request Forgery (CSRF) attack against websites that rely only on the Referer header.
Lifting embargo
This issue was addressed in: Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2007-1084.html http://rhn.redhat.com/errata/RHSA-2007-1082.html http://rhn.redhat.com/errata/RHSA-2007-1083.html