CVE-2005-2968

Publication date 20 September 2005

Last updated 24 July 2024


Ubuntu priority

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
firefox 7.04 feisty
Fixed 2.0.0.6+1-0ubuntu1
6.10 edgy
Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10
6.06 LTS dapper
Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1
mozilla 7.04 feisty Not in release
6.10 edgy
Fixed 1.7.12-1.1ubuntu2
6.06 LTS dapper
Fixed 1.7.12-1.1ubuntu2
mozilla-thunderbird 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-186-1
    • Mozilla and Firefox vulnerabilities
    • 23 September 2005
    • USN-200-1
    • Thunderbird vulnerabilities
    • 11 October 2005

Other references