Affected Versions:
Mozilla Firefox 3.6.
Mozilla Firefox 3.5.x
Mozilla Firefox 3.0.x
Mozilla Thunderbird 3.0
Mozilla SeaMonkey 2.0
Vulnerability description:
Firefox is a popular open-source WEB browser.
Firefox's addEventListener and setTimeout implementations have security vulnerabilities. You can use encapsulated objects to bypass the fix provided by MFSA 3.6-19 to execute cross-site scripting attacks. due to changes in the Firefox browser engine, attacks against this version are limited to capturing keyboard hitting events from cross-source frames or windows. <* Reference
Moz_bug_r_a4 (moz_bug_r_a4@yahoo.com)
Link: http://secunia.com/advisories/38608/
Http://www.mozilla.org/security/announce/2010/mfsa2010-12.html
*>
Security suggestions:
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org ///