1
PublicDateAtUSN: 2008-09-24
2
Candidate: CVE-2008-4068
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4068
6
https://usn.ubuntu.com/usn/usn-645-1
7
https://usn.ubuntu.com/usn/usn-645-2
8
https://usn.ubuntu.com/usn/usn-647-1
10
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and
11
3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12
12
allows remote attackers to bypass "restrictions imposed on local HTML
13
files," and obtain sensitive information and prompt users to write this
14
information into a file, via directory traversal sequences in a resource:
24
upstream_firefox: released (2.0.0.17)
25
dapper_firefox: released (1.5.dfsg+1.5.0.15~prepatch080614e-0ubuntu3)
26
feisty_firefox: released (2.0.0.17+0nobinonly-0ubuntu0.7.4)
27
gutsy_firefox: released (2.0.0.17+1nobinonly-0ubuntu0.7.10)
28
hardy_firefox: released (2.0.0.17+1nobinonly-0ubuntu0.8.04.1)
35
upstream_firefox-3.0: released (3.0.3)
36
dapper_firefox-3.0: DNE
37
feisty_firefox-3.0: DNE
38
gutsy_firefox-3.0: needed (reached end-of-life)
39
lucid_firefox: released (3.0.3+build1+nobinonly-0ubuntu0.8.04.1)
40
maverick_firefox: released (3.0.3+build1+nobinonly-0ubuntu0.8.04.1)
41
natty_firefox: released (3.0.3+build1+nobinonly-0ubuntu0.8.04.1)
42
devel_firefox: released (3.0.3+build1+nobinonly-0ubuntu0.8.04.1)
43
hardy_firefox-3.0: released (3.0.3+build1+nobinonly-0ubuntu0.8.04.1)
44
intrepid_firefox-3.0: released (3.0.3+build1+nobinonly-0ubuntu1)
45
jaunty_firefox-3.0: released (3.0.3+build1+nobinonly-0ubuntu1)
46
karmic_firefox-3.0: DNE
47
lucid_firefox-3.0: DNE
48
maverick_firefox-3.0: DNE
49
natty_firefox-3.0: DNE
50
devel_firefox-3.0: DNE
54
upstream_xulrunner: needs-triage
56
feisty_xulrunner: needed (reached end-of-life)
57
gutsy_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1)
58
hardy_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1)
59
intrepid_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1)
60
jaunty_xulrunner: ignored (reached end-of-life)
61
karmic_xulrunner: ignored (reached end-of-life)
63
maverick_xulrunner: DNE
67
Patches_xulrunner-1.9:
68
upstream_xulrunner-1.9: released (1.9.0.3)
69
dapper_xulrunner-1.9: DNE
70
feisty_xulrunner-1.9: DNE
71
gutsy_xulrunner-1.9: needed (reached end-of-life)
72
hardy_xulrunner-1.9: released (1.9.0.3+build1+nobinonly-0ubuntu0.8.04.1)
73
intrepid_xulrunner-1.9: released (1.9.0.3+build1+nobinonly-0ubuntu2)
74
jaunty_xulrunner-1.9: released (1.9.0.3+build1+nobinonly-0ubuntu2)
75
karmic_xulrunner-1.9: DNE
76
lucid_xulrunner-1.9: DNE
77
maverick_xulrunner-1.9: DNE
78
natty_xulrunner-1.9: DNE
79
devel_xulrunner-1.9: DNE
83
upstream_seamonkey: released (1.1.12)
87
hardy_seamonkey: released (1.1.12+nobinonly-0ubuntu0.8.04.1)
88
intrepid_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
89
jaunty_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
90
karmic_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
91
lucid_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
92
maverick_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
93
natty_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
94
devel_seamonkey: released (1.1.12+nobinonly-0ubuntu1)
97
upstream_iceape: needs-triage
100
gutsy_iceape: needed (reached end-of-life)
112
upstream_thunderbird: released (2.0.0.17)
113
dapper_thunderbird: DNE
114
feisty_thunderbird: DNE
115
gutsy_thunderbird: released (2.0.0.17+nobinonly-0ubuntu0.7.10.1)
116
hardy_thunderbird: released (2.0.0.17+nobinonly-0ubuntu0.8.04.1)
117
intrepid_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
118
jaunty_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
119
karmic_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
120
lucid_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
121
maverick_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
122
natty_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
123
devel_thunderbird: released (2.0.0.17+nobinonly-0ubuntu1)
125
Patches_mozilla-thunderbird:
126
Priority_mozilla-thunderbird: low
127
upstream_mozilla-thunderbird: needs-triage
128
dapper_mozilla-thunderbird: released (1.5.0.13+1.5.0.15~prepatch080614g-0ubuntu0.6.06.1)
129
feisty_mozilla-thunderbird: released (1.5.0.13+1.5.0.15~prepatch080614g-0ubuntu0.7.04.1)
130
gutsy_mozilla-thunderbird: DNE
131
hardy_mozilla-thunderbird: DNE
132
intrepid_mozilla-thunderbird: DNE
133
jaunty_mozilla-thunderbird: DNE
134
karmic_mozilla-thunderbird: DNE
135
lucid_mozilla-thunderbird: DNE
136
maverick_mozilla-thunderbird: DNE
137
natty_mozilla-thunderbird: DNE
138
devel_mozilla-thunderbird: DNE