USN-717-3: Firefox vulnerabilities

11 February 2009

Firefox vulnerabilities




Kojima Hajime discovered that Firefox did not properly handle an escaped null
character. An attacker may be able to exploit this flaw to bypass script
sanitization. (CVE-2008-5510)

Wladimir Palant discovered that Firefox did not restrict access to cookies in
HTTP response headers. If a user were tricked into opening a malicious web
page, a remote attacker could view sensitive information. (CVE-2009-0357)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 6.06

After a standard system upgrade you need to restart Firefox to effect the
necessary changes.

Related notices