CVE-2009-1308
Published: 22 April 2009
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
Notes
Author | Note |
---|---|
jdstrand | CVEs in Firefox are tracked in the xulrunner source packages. The mapping of xulrunner sources to firefox is: xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS xulrunner-1.9: firefox-3.0 xulrunner-1.9.1: firefox-3.5 Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not the system xulrunner-1.9.2, so it is tracked in the firefox source package. this is a new security feature, not a vulnerability per se |
Priority
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Not vulnerable
|
|
upstream |
Needs triage
|
|
seamonkey Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
lucid |
Ignored
|
|
upstream |
Needs triage
|
|
thunderbird Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.8.10.1)
|
|
jaunty |
Released
(2.0.0.22+build1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
lucid |
Released
(2.0.0.22+build1+nobinonly-0ubuntu1.nspr474)
|
|
upstream |
Needs triage
|
|
xulrunner Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
|
|
intrepid |
Ignored
|
|
jaunty |
Ignored
|
|
karmic |
Ignored
|
|
lucid |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Released
(1.9.0.9+nobinonly-0ubuntu0.8.04.1)
|
|
intrepid |
Released
(1.9.0.9+nobinonly-0ubuntu0.8.10.1)
|
|
jaunty |
Released
(1.9.0.9+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
upstream |
Needs triage
|
|
xulrunner-1.9.1 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Released
(1.9.1+nobinonly-0ubuntu0.9.04.1)
|
|
karmic |
Released
(1.9.1~rc2+nobinonly-0ubuntu1)
|
|
lucid |
Does not exist
|
|
upstream |
Needs triage
|