CVE-2014-8639
Publication date 14 January 2015
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 35.0+build3-0ubuntu0.14.04.2
|
|
thunderbird | ||
14.04 LTS trusty |
Fixed 1:31.4.0+build1-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2458-1
- Firefox vulnerabilities
- 14 January 2015
- USN-2460-1
- Thunderbird vulnerabilities
- 19 January 2015