Red Hat Bugzilla – Bug 803113
CVE-2012-0458 Mozilla: Escalation of privilege with Javascript: URL as home page (MFSA 2012-16)
Last modified: 2012-03-14 05:08:26 EDT
Security researcher Mariusz Mlynski reported that an attacker able to convince a potential victim to set a new home page by dragging a link to the "home" button can set that user's home page to a javascript: URL. Once this is done the attacker's page can cause repeated crashes of the browser, eventually getting the script URL loaded in the privileged about:sessionrestore context. Reference: http://www.mozilla.org/security/announce/2012/mfsa2012-16.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:0387 https://rhn.redhat.com/errata/RHSA-2012-0387.html