PublicDate: 2007-04-26 20:19:00 UTC Candidate: CVE-2007-2292 References: http://www.mozilla.org/security/announce/2007/mfsa2007-31.html https://ubuntu.com/security/notices/USN-536-1 https://ubuntu.com/security/notices/USN-535-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2292 Description: CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: upstream_firefox: released (2.0.0.8) dapper_firefox: released (1.5.dfsg+1.5.0.14~prepatch071011b-0ubuntu1) edgy_firefox: released (2.0.0.8+0dfsg-0ubuntu0.6.10) feisty_firefox: released (2.0.0.8+1nobinonly-0ubuntu1) gutsy_firefox: released (2.0.0.8+2nobinonly-0ubuntu1) devel_firefox: not-affected upstream_thunderbird: released (2.0.0.8) dapper_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.6.06) edgy_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.6.10) feisty_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.7.04) gutsy_thunderbird: released (2.0.0.8~pre071022+nobinonly-0ubuntu0.7.10) devel_thunderbird: not-affected upstream_mozilla-thunderbird: needs-triage