CVE-2007-5337
Published: 21 October 2007
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
dapper |
Released
(1.5.dfsg+1.5.0.14~prepatch071011b-0ubuntu1)
|
edgy |
Released
(2.0.0.8+0dfsg-0ubuntu0.6.10)
|
|
feisty |
Released
(2.0.0.8+1nobinonly-0ubuntu1)
|
|
gutsy |
Released
(2.0.0.8+2nobinonly-0ubuntu1)
|
|
upstream |
Released
(2.0.0.8)
|
|
mozilla-thunderbird Launchpad, Ubuntu, Debian |
dapper |
Released
(1.5.0.13+1.5.0.14b-0ubuntu0.6.06)
|
edgy |
Released
(1.5.0.13+1.5.0.14b-0ubuntu0.6.10)
|
|
feisty |
Released
(1.5.0.13+1.5.0.14b-0ubuntu0.7.04)
|
|
upstream |
Needs triage
|
|
thunderbird Launchpad, Ubuntu, Debian |
gutsy |
Released
(2.0.0.8~pre071022+nobinonly-0ubuntu0.7.10)
|
upstream |
Released
(2.0.0.8)
|