CVE-2014-8638
Publication date 14 January 2015
Last updated 24 July 2024
Ubuntu priority
The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 35.0+build3-0ubuntu0.14.04.2
|
|
thunderbird | ||
14.04 LTS trusty |
Fixed 1:31.4.0+build1-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2458-1
- Firefox vulnerabilities
- 14 January 2015
- USN-2460-1
- Thunderbird vulnerabilities
- 19 January 2015