~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
PublicDate: 2007-11-13
Candidate: CVE-2007-5947
References:
 http://www.ubuntu.com/usn/usn-546-1
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947
Description:
 The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey
 before 1.1.7 retrieves the inner URL regardless of its MIME type, and
 considers HTML documents within a jar archive to have the same origin as
 the inner URL, which allows remote attackers to conduct cross-site
 scripting (XSS) attacks via a jar: URI.
Ubuntu-Description:
Notes:
Bugs:
Priority: low
Assigned-to:
upstream_firefox: released (2.0.0.10)
dapper_firefox: released (1.5.dfsg+1.5.0.14~prepatch071125a-0ubuntu1)
edgy_firefox: released (2.0.0.10+0nobinonly-0ubuntu0.6.10)
feisty_firefox: released (2.0.0.10+1nobinonly-0ubuntu1)
gutsy_firefox: released (2.0.0.10+2nobinonly-0ubuntu1.7.10.1)
devel_firefox: not-affected (2.0.0.10+2nobinonly-0ubuntu2)