CVE-2009-0358
Publication date 4 February 2009
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim’s browser, as demonstrated by reading the response page of an https POST request.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 8.10 intrepid | Not in release |
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Not affected
|
|
6.06 LTS dapper |
Not affected
|
|
firefox-3.0 | 8.10 intrepid |
Fixed 3.0.6+nobinonly-0ubuntu0.8.10.1
|
8.04 LTS hardy |
Fixed 3.0.6+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy | Ignored end of life, was needed | |
6.06 LTS dapper | Not in release | |
iceape | 8.10 intrepid | Not in release |
8.04 LTS hardy | Not in release | |
7.10 gutsy |
Not affected
|
|
6.06 LTS dapper | Not in release | |
iceweasel | 8.10 intrepid | Not in release |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
6.06 LTS dapper | Not in release | |
seamonkey | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy | Not in release | |
6.06 LTS dapper | Not in release | |
xulrunner | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Not affected
|
|
6.06 LTS dapper | Not in release | |
xulrunner-1.9 | 8.10 intrepid |
Fixed 1.9.0.6+nobinonly-0ubuntu0.8.10.1
|
8.04 LTS hardy |
Fixed 1.9.0.6+nobinonly-0ubuntu0.8.04.1
|
|
7.10 gutsy | Ignored end of life, was needed | |
6.06 LTS dapper | Not in release |