Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-5510

Опубликовано: 17 дек. 2008
Источник: debian

Описание

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed3.0.5-1package
icedovefixed2.0.0.19-1package
iceapefixed1.1.14-1package
iceapeend-of-lifeetchpackage
xulrunnerfixed1.9.0.5-1package
xulrunnerend-of-lifeetchpackage

Примечания

  • patch will be checked for icedove/iceape/xulrunner by Alexander for next round

Связанные уязвимости

ubuntu
больше 16 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

redhat
больше 16 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

nvd
больше 16 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

github
около 3 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

oracle-oval
больше 16 лет назад

ELSA-2008-1036: firefox security update (CRITICAL)