CVE-2008-5503

Published: 17 December 2008

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

Priority

Low

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream Needs triage

firefox-3.0
Launchpad, Ubuntu, Debian
Upstream
Released (3.0.5)
iceape
Launchpad, Ubuntu, Debian
Upstream
Released (1.1.14)
mozilla-thunderbird
Launchpad, Ubuntu, Debian
Upstream Needs triage

seamonkey
Launchpad, Ubuntu, Debian
Upstream
Released (1.1.14)
thunderbird
Launchpad, Ubuntu, Debian
Upstream
Released (2.0.0.19)
xulrunner-1.9
Launchpad, Ubuntu, Debian
Upstream
Released (1.9.0.5)