CVE-2014-8639
Published: 14 January 2015
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
lucid |
Ignored
(reached end of life)
|
precise |
Released
(35.0+build3-0ubuntu0.12.04.2)
|
|
trusty |
Does not exist
(trusty was released [35.0+build3-0ubuntu0.14.04.2])
|
|
upstream |
Released
(35.0)
|
|
utopic |
Released
(35.0+build3-0ubuntu0.14.10.2)
|
|
thunderbird Launchpad, Ubuntu, Debian |
lucid |
Ignored
(reached end-of-life)
|
precise |
Released
(1:31.4.0+build1-0ubuntu0.12.04.1)
|
|
trusty |
Does not exist
(trusty was released [1:31.4.0+build1-0ubuntu0.14.04.1])
|
|
upstream |
Released
(31.4.0)
|
|
utopic |
Released
(1:31.4.0+build1-0ubuntu0.14.10.1)
|