~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2010-0172

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2010-0172
2
 
PublicDate: 2010-03-25
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0172
5
 
 http://www.mozilla.org/security/announce/2010/mfsa2010-15.html
6
 
Description:
7
 
 toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the
8
 
 asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6
9
 
 before 3.6.2 does not properly handle concurrent authorization requests
10
 
 from multiple web sites, which might allow remote web servers to spoof an
11
 
 authorization dialog and capture credentials by demanding HTTP
12
 
 authentication in opportunistic circumstances.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
 https://bugzilla.mozilla.org/show_bug.cgi?id=537862
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to: chrisccoulson
20
 
 
21
 
Patches_firefox:
22
 
upstream_firefox: released (3.6.2)
23
 
dapper_firefox: ignored (reached end-of-life)
24
 
hardy_firefox: not-affected
25
 
intrepid_firefox: DNE
26
 
jaunty_firefox: DNE
27
 
karmic_firefox: DNE
28
 
devel_firefox: released (3.6.3+nobinonly-0ubuntu2)
29