CVE-2008-0593
Publication date 9 February 2008
Last updated 24 July 2024
Ubuntu priority
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 8.10 intrepid | Not in release |
8.04 LTS hardy |
Fixed 2.0.0.12+2nobinonly+2-0ubuntu3
|
|
7.10 gutsy |
Fixed 2.0.0.12+2nobinonly+2-0ubuntu0.7.10
|
|
7.04 feisty |
Fixed 2.0.0.12+1nobinonly+2-0ubuntu0.7.4
|
|
6.10 edgy |
Fixed 2.0.0.12+0nobinonly+2-0ubuntu0.6.10
|
|
6.06 LTS dapper |
Fixed 1.5.dfsg+1.5.0.15~prepatch080202a-0ubuntu1
|
|
iceape | 8.10 intrepid | Not in release |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Ignored end of life, was needs-triage | |
7.04 feisty | Not in release | |
6.10 edgy | Not in release | |
6.06 LTS dapper | Not in release | |
iceweasel | 8.10 intrepid | Not in release |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.10 edgy | Not in release | |
6.06 LTS dapper | Not in release | |
seamonkey | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.10 edgy | Not in release | |
6.06 LTS dapper | Not in release | |
xulrunner | 8.10 intrepid |
Fixed 1.8.1.13+nobinonly-0ubuntu1
|
8.04 LTS hardy |
Fixed 1.8.1.13+nobinonly-0ubuntu1
|
|
7.10 gutsy |
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1
|
|
7.04 feisty | Ignored end of life, was needs-triage | |
6.10 edgy | Ignored end of life, was needs-triage | |
6.06 LTS dapper | Not in release |