Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-7293

Опубликовано: 09 авг. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

released

3.6.23+build1+nobinonly-0ubuntu0.10.04.1
maverick

released

3.6.23+build1+nobinonly-0ubuntu0.10.04.1
natty

not-affected

7.0.1+build1+nobinonly-0ubuntu0.11.04.1
oneiric

not-affected

upstream

released

3.6

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

released

3.6.17+build3+nobinonly-0ubuntu0.8.04.1
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

needs-triage

Ubuntu source uses 3.6.x

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

needs-triage

Ubuntu source uses 3.6.x

Показывать по

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

DNE

maverick

DNE

natty

not-affected

oneiric

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 68%
0.00586
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

nvd
больше 14 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

debian
больше 14 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to coo ...

github
больше 3 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

EPSS

Процентиль: 68%
0.00586
Низкий

5.8 Medium

CVSS2