Red Hat Bugzilla – Bug 730520
CVE-2011-2981 Mozilla: Privilege escalation using event handlers
Last modified: 2016-03-01 04:44:16 EST
Mozilla security researcher moz_bug_r_a_4 reported a vulnerability in event management code that would permit JavaScript to be run in the wrong context, including that of a different website or potentially in a chrome-privileged context.
This is now public: http://www.mozilla.org/security/announce/2011/mfsa2011-30.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2011:1164 https://rhn.redhat.com/errata/RHSA-2011-1164.html