~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2008-1238

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2008-03-27
2
 
Candidate: CVE-2008-1238
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1238
5
 
 https://usn.ubuntu.com/usn/usn-592-1
6
 
Description:
7
 
 Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating
8
 
 the HTTP Referer header, does not list the entire URL when it contains
9
 
 Basic Authentication credentials without a username, which makes it easier
10
 
 for remote attackers to bypass application protection mechanisms that rely
11
 
 on Referer headers, such as with some Cross-Site Request Forgery (CSRF)
12
 
 mechanisms.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: low
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_firefox:
21
 
upstream_firefox: 2.0.0.13
22
 
dapper_firefox: released (1.5.dfsg+1.5.0.15~prepatch080323a-0ubuntu1)
23
 
edgy_firefox: released (2.0.0.13+0nobinonly-0ubuntu0.6.10)
24
 
feisty_firefox: released (2.0.0.13+0nobinonly-0ubuntu0.7.4)
25
 
gutsy_firefox: released (2.0.0.13+1nobinonly-0ubuntu0.7.10)
26
 
hardy_firefox: released (2.0.0.13+1nobinonly-0ubuntu1)
27
 
intrepid_firefox: DNE
28
 
devel_firefox: DNE
29
 
 
30
 
Patches_xulrunner:
31
 
upstream_xulrunner: needs-triage
32
 
dapper_xulrunner: DNE
33
 
edgy_xulrunner: needed (reached end-of-life)
34
 
feisty_xulrunner: needed (reached end-of-life)
35
 
gutsy_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1)
36
 
hardy_xulrunner: released (1.8.1.13+nobinonly-0ubuntu1)
37
 
intrepid_xulrunner: released (1.8.1.13+nobinonly-0ubuntu1)
38
 
devel_xulrunner: released (1.8.1.13+nobinonly-0ubuntu1)
39
 
 
40
 
Patches_iceape:
41
 
upstream_iceape: 1.1.9
42
 
dapper_iceape: DNE
43
 
edgy_iceape: DNE
44
 
feisty_iceape: DNE
45
 
gutsy_iceape: needed (reached end-of-life)
46
 
hardy_iceape: DNE
47
 
intrepid_iceape: DNE
48
 
devel_iceape: DNE
49
 
 
50
 
Patches_iceweasel:
51
 
upstream_iceweasel: needs-triage
52
 
dapper_iceweasel: DNE
53
 
edgy_iceweasel: DNE
54
 
feisty_iceweasel: DNE
55
 
gutsy_iceweasel: DNE
56
 
hardy_iceweasel: DNE
57
 
intrepid_iceweasel: DNE
58
 
devel_iceweasel: DNE
59
 
 
60
 
Patches_seamonkey:
61
 
upstream_seamonkey: 1.1.9
62
 
dapper_seamonkey: DNE
63
 
edgy_seamonkey: DNE
64
 
feisty_seamonkey: DNE
65
 
gutsy_seamonkey: DNE
66
 
hardy_seamonkey: released (1.1.9+nobinonly-0ubuntu1)
67
 
intrepid_seamonkey: released (1.1.9+nobinonly-0ubuntu1)
68
 
devel_seamonkey: released (1.1.9+nobinonly-0ubuntu1)
69