Tracker / CVE-2012-0450
CVE-2012-0450
Low 2.1
Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.
Affected products and versions
| mozilla | firefox |
|---|---|
| mozilla | seamonkey |
| mozilla | seamonkey · … → 2.7 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.