CVE-2005-1157

Publication date 2 May 2005

Last updated 24 July 2024


Ubuntu priority

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."

Status

Package Ubuntu Release Status
mozilla 7.10 gutsy Not in release
7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-124-1
    • Mozilla and Firefox vulnerabilities
    • 11 May 2005
    • USN-149-3
    • Ubuntu 4.10 update for Firefox vulnerabilities
    • 28 July 2005

Other references