---
title: "CVE-2009-2654\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-2654?format=md
keywords: index, follow
---

# CVE-2009-2654

Publication date 3 August 2009

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote
attackers to spoof the address bar, and possibly conduct phishing attacks,
via a crafted web page that calls window.open with an invalid character in
the URL, makes document.write calls to the resulting object, and then calls
the stop method during the loading of the error page.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox-3.0 | 9.04 jaunty | Fixed 3.0.13+nobinonly-0ubuntu0.9.04.1 |
| 8.10 intrepid | Fixed 3.0.13+nobinonly-0ubuntu0.8.10.1 |
| 8.04 LTS hardy | Fixed 3.0.13+nobinonly-0ubuntu0.8.04.1 |
| 6.06 LTS dapper | Not in release |
| firefox-3.5 | 9.04 jaunty | Fixed 3.5.2+nobinonly-0ubuntu0.9.04.1 |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| xulrunner-1.9 | 9.04 jaunty | Fixed 1.9.0.13+nobinonly-0ubuntu0.9.04.1 |
| 8.10 intrepid | Fixed 1.9.0.13+nobinonly-0ubuntu0.8.10.1 |
| 8.04 LTS hardy | Fixed 1.9.0.13+nobinonly-0ubuntu0.8.04.1 |
| 6.06 LTS dapper | Not in release |
| xulrunner-1.9.1 | 9.04 jaunty | Fixed 1.9.1.2+nobinonly-0ubuntu0.9.04.1 |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-2654)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-2654)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-2654)

### Related Ubuntu Security Notices (USN)

+ [USN-811-1](https://usn.ubuntu.com/USN-811-1)
+ Firefox and Xulrunner vulnerability
+ 8 August 2009

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-2654>
