Red Hat Bugzilla – Bug 851927
CVE-2012-3974 Mozilla: Installer will launch incorrect executable following new installation (MFSA 2012-67)
Last modified: 2012-08-28 23:06:37 EDT
Security researcher Masato Kinugawa reported that if a crafted executable is placed in the root partition on a Windows file system, the Firefox and Thunderbird installer will launch this program after a standard installation instead of Firefox or Thunderbird, running this program with the user's privileges. This issue does not affect the linux version of Firefox and Thunderbird. Reference: http://www.mozilla.org/security/announce/2012/mfsa2012-67.html Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Mozilla security researcher Masato Kinugawa as the original reporter of this flaw. Statement: This issue does not affect the version of Firefox and Thunderbird package, as shipped with Red Hat Enterprise Linux 5 and 6.