~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-5593

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2013-10-29
2
 
Candidate: CVE-2013-5593
3
 
PublicDate: 2013-10-30
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5593
6
 
 http://www.mozilla.org/security/announce/2013/mfsa2013-94.html
7
 
 https://usn.ubuntu.com/usn/usn-2009-1
8
 
 https://usn.ubuntu.com/usn/usn-2010-1
9
 
Description:
10
 
 The SELECT element implementation in Mozilla Firefox before 25.0, Firefox
11
 
 ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22
12
 
 does not properly restrict the nature or placement of HTML within a
13
 
 dropdown menu, which allows remote attackers to spoof the address bar or
14
 
 conduct clickjacking attacks via vectors that trigger navigation off of a
15
 
 page containing this element.
16
 
Ubuntu-Description: 
17
 
Notes: 
18
 
Bugs: 
19
 
Priority: low
20
 
Discovered-by:
21
 
Assigned-to: chrisccoulson
22
 
 
23
 
Patches_firefox:
24
 
upstream_firefox: released (25.0)
25
 
lucid_firefox: ignored (reached end-of-life)
26
 
precise_firefox: released (25.0+build3-0ubuntu0.12.04.1)
27
 
quantal_firefox: released (25.0+build3-0ubuntu0.12.10.1)
28
 
raring_firefox: released (25.0+build3-0ubuntu0.13.04.1)
29
 
saucy_firefox: released (25.0+build3-0ubuntu0.13.10.1)
30
 
devel_firefox: released (25.0+build3-0ubuntu0.13.10.1)
31
 
 
32
 
Patches_thunderbird:
33
 
upstream_thunderbird: released (24.1.0)
34
 
lucid_thunderbird: ignored (reached end-of-life)
35
 
precise_thunderbird: released (1:24.1.0+build1-0ubuntu0.12.04.1)
36
 
quantal_thunderbird: released (1:24.1.0+build1-0ubuntu0.12.10.1)
37
 
raring_thunderbird: released (1:24.1.0+build1-0ubuntu0.13.04.1)
38
 
saucy_thunderbird: released (1:24.1.0+build1-0ubuntu0.13.10.1)
39
 
devel_thunderbird: released (1:24.1.1+build1-0ubuntu0.13.10.1)