Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27610
HistoryFeb 03, 2012 - 12:00 a.m.

Mozilla Foundation Security Advisory 2012-09

2012-02-0300:00:00
vulners.com
20

Mozilla Foundation Security Advisory 2012-09

Title: Firefox Recovery Key.html is saved with unsafe permission
Impact: Moderate
Announced: January 31, 2012
Reporter: magicant starmen
Products: Firefox, SeaMonkey

Fixed in: Firefox 10.0
SeaMonkey 2.7
Description

magicant starmen reported that if a user chooses to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users on Linux and OS X systems.

Firefox 3.6 is not affected by this vulnerability.

References

"Firefox Recovery Key.html" is saved with unsafe permission
CVE-2012-0450