CVE-2015-4520
Publication date 22 September 2015
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 41.0+build3-0ubuntu0.14.04.1
|
|
thunderbird | ||
14.04 LTS trusty |
Fixed 1:38.3.0+build1-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2754-1
- Thunderbird vulnerabilities
- 5 October 2015
- USN-2743-1
- Firefox vulnerabilities
- 22 September 2015