CVE-2011-0082

Publication date 6 June 2011

Last updated 24 July 2024


Ubuntu priority

Description

The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.

Status

Package Ubuntu Release Status
firefox 11.10 oneiric
Not affected
11.04 natty
Fixed 4.0.1+build1+nobinonly-0ubuntu0.11.04.1
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life