CVE-2005-4874

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

Description

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.

Status

Package Ubuntu Release Status
mozilla 7.10 gutsy Not in release
7.04 feisty Not in release
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
seamonkey 7.10 gutsy Not in release
7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities