CVE-2005-1531
Publication date 12 May 2005
Last updated 17 July 2025
Ubuntu priority
Description
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via “Wrapped” javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) “a nested variant.”
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release | |
| 6.06 LTS dapper | Not in release | |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release | |
| 6.06 LTS dapper | Not in release | |
| firefox | 7.04 feisty |
Not affected
|
| 6.10 edgy |
Not affected
|
|
| 6.06 LTS dapper |
Not affected
|
|
| firefox-granparadiso | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release | |
| 6.06 LTS dapper | Not in release | |
| mozilla | 7.04 feisty | Not in release |
| 6.10 edgy |
Fixed 1.7.13-0.2ubuntu1
|
|
| 6.06 LTS dapper |
Not affected
|