~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2009-0357

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2009-02-04
2
 
Candidate: CVE-2009-0357
3
 
PublicDate: 2009-02-04
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357
6
 
 https://usn.ubuntu.com/usn/usn-717-1
7
 
 https://usn.ubuntu.com/usn/usn-717-3
8
 
 https://usn.ubuntu.com/usn/usn-717-2
9
 
Description:
10
 
 Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly
11
 
 restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2
12
 
 HTTP response headers, which allows remote attackers to obtain sensitive
13
 
 information from cookies via XMLHttpRequest calls, related to the HTTPOnly
14
 
 protection mechanism.
15
 
Ubuntu-Description:
16
 
Notes:
17
 
 jdstrand> CVEs in Firefox are tracked in the xulrunner source packages. The
18
 
  mapping of xulrunner sources to firefox is:
19
 
   xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS
20
 
   xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS
21
 
   xulrunner-1.9: firefox-3.0
22
 
   xulrunner-1.9.1: firefox-3.5
23
 
 jdstrand: Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not
24
 
  the system xulrunner-1.9.2, so it is tracked in the firefox source package.
25
 
Bugs:
26
 
Priority: medium
27
 
Discovered-by: Wladimir Palant
28
 
Assigned-to: asac
29
 
 
30
 
Patches_firefox:
31
 
upstream_firefox: needs-triage
32
 
dapper_firefox: released (1.5.dfsg+1.5.0.15~prepatch080614j-0ubuntu1)
33
 
gutsy_firefox: released (2.0.0.21~20090209t122238+nobinonly-0ubuntu0.7.10.1)
34
 
hardy_firefox: ignored (uses system xulrunner)
35
 
intrepid_firefox: DNE
36
 
jaunty_firefox: DNE
37
 
karmic_firefox: DNE
38
 
lucid_firefox: not-affected
39
 
maverick_firefox: not-affected
40
 
natty_firefox: not-affected
41
 
devel_firefox: not-affected
42
 
 
43
 
Patches_xulrunner:
44
 
upstream_xulrunner: needs-triage
45
 
dapper_xulrunner: DNE
46
 
gutsy_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1)
47
 
hardy_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1)
48
 
intrepid_xulrunner: released (1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1)
49
 
jaunty_xulrunner: ignored (reached end-of-life)
50
 
karmic_xulrunner: ignored (reached end-of-life)
51
 
lucid_xulrunner: DNE
52
 
maverick_xulrunner: DNE
53
 
natty_xulrunner: DNE
54
 
devel_xulrunner: DNE
55
 
 
56
 
Patches_xulrunner-1.9:
57
 
upstream_xulrunner-1.9: needs-triage
58
 
dapper_xulrunner-1.9: DNE
59
 
gutsy_xulrunner-1.9: needed (reached end-of-life)
60
 
hardy_xulrunner-1.9: released (1.9.0.6+nobinonly-0ubuntu0.8.04.1)
61
 
intrepid_xulrunner-1.9: released (1.9.0.6+nobinonly-0ubuntu0.8.10.1)
62
 
jaunty_xulrunner-1.9: released (1.9.0.6+nobinonly-0ubuntu1)
63
 
karmic_xulrunner-1.9: DNE
64
 
lucid_xulrunner-1.9: DNE
65
 
maverick_xulrunner-1.9: DNE
66
 
natty_xulrunner-1.9: DNE
67
 
devel_xulrunner-1.9: DNE
68
 
 
69
 
 
70
 
Patches_seamonkey:
71
 
upstream_seamonkey: released (1.1.15)
72
 
dapper_seamonkey: DNE
73
 
gutsy_seamonkey: DNE
74
 
hardy_seamonkey: released (1.1.15+nobinonly-0ubuntu0.8.04.2)
75
 
intrepid_seamonkey: released (1.1.15+nobinonly-0ubuntu0.8.10.2)
76
 
jaunty_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
77
 
karmic_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
78
 
lucid_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
79
 
maverick_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
80
 
natty_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
81
 
devel_seamonkey: released (1.1.15+nobinonly-0ubuntu2)
82
 
 
83
 
Patches_iceape:
84
 
upstream_iceape: needs-triage
85
 
dapper_iceape: DNE
86
 
gutsy_iceape: needed (reached end-of-life)
87
 
hardy_iceape: DNE
88
 
intrepid_iceape: DNE
89
 
jaunty_iceape: DNE
90
 
karmic_iceape: DNE
91
 
lucid_iceape: DNE
92
 
maverick_iceape: DNE
93
 
natty_iceape: DNE
94
 
devel_iceape: DNE
95
 
 
96