---
title: "CVE-2009-0358\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-0358?format=md
keywords: index, follow
---

# CVE-2009-0358

Publication date 4 February 2009

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1)
no-store and (2) no-cache Cache-Control directives, which allows local
users to obtain sensitive information by using the (a) back button or (b)
history list of the victim's browser, as demonstrated by reading the
response page of an https POST request.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not affected |
| 6.06 LTS dapper | Not affected |
| firefox-3.0 | 8.10 intrepid | Fixed 3.0.6+nobinonly-0ubuntu0.8.10.1 |
| 8.04 LTS hardy | Fixed 3.0.6+nobinonly-0ubuntu0.8.04.1 |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |
| iceape | 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not affected |
| 6.06 LTS dapper | Not in release |
| iceweasel | 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 6.06 LTS dapper | Not in release |
| seamonkey | 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not in release |
| 6.06 LTS dapper | Not in release |
| xulrunner | 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not affected |
| 6.06 LTS dapper | Not in release |
| xulrunner-1.9 | 8.10 intrepid | Fixed 1.9.0.6+nobinonly-0ubuntu0.8.10.1 |
| 8.04 LTS hardy | Fixed 1.9.0.6+nobinonly-0ubuntu0.8.04.1 |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0358)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-0358)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-0358)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-0358)

### Related Ubuntu Security Notices (USN)

+ [USN-717-1](https://usn.ubuntu.com/USN-717-1)
+ Firefox and Xulrunner vulnerabilities
+ 10 February 2009

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-0358>
