CVE-2008-4066
Publication date 24 September 2008
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a “jav�ascript” sequence, aka “HTML escaped low surrogates bug.”
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 11.04 natty |
Fixed 3.0.3+build1+nobinonly-0ubuntu0.8.04.1
|
10.10 maverick |
Fixed 3.0.3+build1+nobinonly-0ubuntu0.8.04.1
|
|
10.04 LTS lucid |
Fixed 3.0.3+build1+nobinonly-0ubuntu0.8.04.1
|
|
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy |
Fixed 2.0.0.17+1nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy |
Fixed 2.0.0.17+1nobinonly-0ubuntu0.7.10
|
|
7.04 feisty |
Fixed 2.0.0.17+0nobinonly-0ubuntu0.7.4
|
|
6.06 LTS dapper |
Fixed 1.5.dfsg+1.5.0.15~prepatch080614e-0ubuntu3
|
|
firefox-3.0 | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty |
Fixed 3.0.3+build1+nobinonly-0ubuntu1
|
|
8.10 intrepid |
Fixed 3.0.3+build1+nobinonly-0ubuntu1
|
|
8.04 LTS hardy |
Fixed 3.0.3+build1+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
iceape | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
mozilla-thunderbird | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty |
Fixed 1.5.0.13+1.5.0.15~prepatch080614g-0ubuntu0.7.04.1
|
|
6.06 LTS dapper |
Fixed 1.5.0.13+1.5.0.15~prepatch080614g-0ubuntu0.6.06.1
|
|
seamonkey | 11.04 natty |
Fixed 1.1.12+nobinonly-0ubuntu1
|
10.10 maverick |
Fixed 1.1.12+nobinonly-0ubuntu1
|
|
10.04 LTS lucid |
Fixed 1.1.12+nobinonly-0ubuntu1
|
|
9.10 karmic |
Fixed 1.1.12+nobinonly-0ubuntu1
|
|
9.04 jaunty |
Fixed 1.1.12+nobinonly-0ubuntu1
|
|
8.10 intrepid |
Fixed 1.1.12+nobinonly-0ubuntu1
|
|
8.04 LTS hardy |
Fixed 1.1.12+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy | Not in release | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
thunderbird | 11.04 natty |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
10.10 maverick |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
|
10.04 LTS lucid |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
|
9.10 karmic |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
|
9.04 jaunty |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
|
8.10 intrepid |
Fixed 2.0.0.17+nobinonly-0ubuntu1
|
|
8.04 LTS hardy |
Fixed 2.0.0.17+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy |
Fixed 2.0.0.17+nobinonly-0ubuntu0.7.10.1
|
|
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release | |
xulrunner | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid |
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1
|
|
8.04 LTS hardy |
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1
|
|
7.10 gutsy |
Fixed 1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1
|
|
7.04 feisty | Ignored end of life, was needed | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9 | 11.04 natty | Not in release |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty |
Fixed 1.9.0.3+build1+nobinonly-0ubuntu2
|
|
8.10 intrepid |
Fixed 1.9.0.3+build1+nobinonly-0ubuntu2
|
|
8.04 LTS hardy |
Fixed 1.9.0.3+build1+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release |