CVE-2008-5913
Publication date 20 January 2009
Last updated 24 July 2024
Ubuntu priority
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a “temporary footprint” and an “in-session phishing attack.”
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 10.04 LTS lucid |
Fixed 3.6.6+nobinonly-0ubuntu0.10.04.1
|
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
xulrunner-1.9 | 10.04 LTS lucid | Not in release |
9.10 karmic | Not in release | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9.1 | 10.04 LTS lucid | Not in release |
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9.2 | 10.04 LTS lucid |
Fixed 1.9.2.6+nobinonly-0ubuntu0.10.04.1
|
9.10 karmic |
Fixed 1.9.2.7+build2+nobinonly-0ubuntu0.9.10.2
|
|
9.04 jaunty |
Fixed 1.9.2.7+build2+nobinonly-0ubuntu0.9.04.2
|
|
8.10 intrepid | Not in release | |
8.04 LTS hardy |
Fixed 1.9.2.6+nobinonly-0ubuntu0.8.04.1
|
|
6.06 LTS dapper | Not in release |