CVE-2005-2263

Publication date 13 July 2005

Last updated 24 July 2024


Ubuntu priority

The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.

Status

Package Ubuntu Release Status
mozilla 7.04 feisty Not in release
6.10 edgy
Fixed 1.7.12-1.1ubuntu2
6.06 LTS dapper
Fixed 1.7.12-1.1ubuntu2

References

Related Ubuntu Security Notices (USN)

    • USN-155-1
    • Mozilla vulnerabilities
    • 27 July 2005
    • USN-149-3
    • Ubuntu 4.10 update for Firefox vulnerabilities
    • 28 July 2005
    • USN-149-1
    • Firefox vulnerabilities
    • 21 July 2005

Other references