{
  "threat_severity" : "Moderate",
  "public_date" : "2012-08-28T00:00:00Z",
  "bugzilla" : {
    "description" : "Mozilla: Location object security checks bypassed by chrome code (MFSA 2012-70)",
    "id" : "851937",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=851937"
  },
  "cvss" : {
    "cvss_base_score" : "5.1",
    "cvss_scoring_vector" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "details" : [ "The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code." ],
  "acknowledgement" : "Red Hat would like to thank Mozilla project for reporting this issue. Upstream acknowledges moz_bug_r_a4 as the original reporter.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1210",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "firefox-0:10.0.7-1.el5_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1210",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "xulrunner-0:10.0.7-2.el5_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1211",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "thunderbird-0:10.0.7-1.el5_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1210",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "firefox-0:10.0.7-1.el6_3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1210",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "xulrunner-0:10.0.7-1.el6_3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2012-08-29T00:00:00Z",
    "advisory" : "RHSA-2012:1211",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "thunderbird-0:10.0.7-1.el6_3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2012-3978\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-3978" ],
  "name" : "CVE-2012-3978",
  "csaw" : false
}