CVE-2005-2269

Publication date 13 July 2005

Last updated 24 July 2024


Ubuntu priority

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

Status

Package Ubuntu Release Status
mozilla 7.04 feisty Not in release
6.10 edgy
Fixed 1.7.12-1.1ubuntu2
6.06 LTS dapper
Fixed 1.7.12-1.1ubuntu2
mozilla-thunderbird 7.04 feisty
Fixed 1.5.0.13-0ubuntu0.7.04
6.10 edgy
Fixed 1.5.0.13-0ubuntu0.6.10
6.06 LTS dapper
Fixed 1.5.0.13-0ubuntu0.6.06

References

Related Ubuntu Security Notices (USN)

    • USN-155-1
    • Mozilla vulnerabilities
    • 27 July 2005
    • USN-157-1
    • Mozilla Thunderbird vulnerabilities
    • 1 August 2005
    • USN-149-1
    • Firefox vulnerabilities
    • 21 July 2005
    • USN-149-3
    • Ubuntu 4.10 update for Firefox vulnerabilities
    • 28 July 2005

Other references