Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thunderbird_esr | Mozilla | 17.0 (including) | 17.0 (including) |
Thunderbird_esr | Mozilla | 17.0.1 (including) | 17.0.1 (including) |
Thunderbird_esr | Mozilla | 17.0.2 (including) | 17.0.2 (including) |
Thunderbird_esr | Mozilla | 17.0.3 (including) | 17.0.3 (including) |
Thunderbird_esr | Mozilla | 17.0.4 (including) | 17.0.4 (including) |
Thunderbird_esr | Mozilla | 17.0.5 (including) | 17.0.5 (including) |
Thunderbird_esr | Mozilla | 17.0.6 (including) | 17.0.6 (including) |
Thunderbird_esr | Mozilla | 17.0.7 (including) | 17.0.7 (including) |
Thunderbird_esr | Mozilla | 17.0.8 (including) | 17.0.8 (including) |