CVE-2011-2372
Published: 28 September 2011
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
hardy |
Ignored
(uses system xulrunner)
|
lucid |
Released
(3.6.23+build1+nobinonly-0ubuntu0.10.04.1)
|
|
maverick |
Released
(3.6.23+build1+nobinonly-0ubuntu0.10.10.1)
|
|
natty |
Released
(7.0.1+build1+nobinonly-0ubuntu0.11.04.1)
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
raring |
Not vulnerable
|
|
saucy |
Not vulnerable
|
|
upstream |
Released
(3.6.23, 7.0)
|
|
firefox-3.0 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
(Ubuntu source uses 3.6.x)
|
|
firefox-3.5 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needs triage
(Ubuntu source uses 3.6.x)
|
|
seamonkey Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Ignored
(reached end-of-life)
|
|
maverick |
Ignored
(reached end-of-life)
|
|
natty |
Ignored
(reached end-of-life)
|
|
oneiric |
Not vulnerable
(2.4.1-0ubuntu1)
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Released
(2.4)
|
|
thunderbird Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Released
(3.1.15+build1+nobinonly-0ubuntu0.10.04.1)
|
|
maverick |
Released
(3.1.15+build1+nobinonly-0ubuntu0.10.10.1)
|
|
natty |
Released
(3.1.15+build1+nobinonly-0ubuntu0.11.04.1)
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
raring |
Not vulnerable
|
|
saucy |
Not vulnerable
|
|
upstream |
Released
(3.1.5, 7.0)
|
|
xulrunner-1.9.2 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(reached end-of-life)
|
lucid |
Released
(1.9.2.23+build1+nobinonly-0ubuntu0.10.04.1)
|
|
maverick |
Released
(1.9.2.23+build1+nobinonly-0ubuntu0.10.10.1)
|
|
natty |
Released
(1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Released
(1.9.2.23)
|
|
xulrunner-2.0 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Ignored
(reached end-of-life)
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
saucy |
Does not exist
|
|
upstream |
Needed
|