CVE-2013-5612

Priority
Low
Description
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and
SeaMonkey before 2.23 makes it easier for remote attackers to inject
arbitrary web script or HTML by leveraging a Same Origin Policy violation
triggered by lack of a charset parameter in a Content-Type HTTP header.
References
Assigned-to
chrisccoulson
Package
Upstream:released (26.0)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (26.0+build2-0ubuntu0.12.04.2)
Ubuntu 12.10 (Quantal Quetzal):released (26.0+build2-0ubuntu0.12.10.2)
Ubuntu 13.04 (Raring Ringtail):released (26.0+build2-0ubuntu0.13.04.2)
Ubuntu 13.10 (Saucy Salamander):released (26.0+build2-0ubuntu0.13.10.2)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected
More Information

Valid XHTML 1.0 Strict

Updated: 2013-12-11 18:14:50 UTC (commit 7535)