CVE-2008-5506

Publication date 17 December 2008

Last updated 24 July 2024


Ubuntu priority

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."

Status

Package Ubuntu Release Status

References

Related Ubuntu Security Notices (USN)

    • USN-690-1
    • Firefox and xulrunner vulnerabilities
    • 17 December 2008
    • USN-690-3
    • Firefox vulnerabilities
    • 18 December 2008
    • USN-690-2
    • Firefox vulnerabilities
    • 18 December 2008
    • USN-701-1
    • Thunderbird vulnerabilities
    • 6 January 2009
    • USN-701-2
    • Thunderbird vulnerabilities
    • 6 January 2009

Other references