Your submission was sent successfully! Close

CVE-2013-1696

Published: 25 June 2013

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

Priority

Low

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise
Released (22.0+build1-0ubuntu0.12.04.1)
quantal
Released (22.0+build1-0ubuntu0.12.10.1)
raring
Released (22.0+build1-0ubuntu0.13.04.1)
upstream
Released (22.0)