CVE-2007-0802

Publication date 7 February 2007

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the ”.” and ”/” characters, which is not caught by the Phishing List blacklist filter.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
firefox 8.10 intrepid Not in release
8.04 LTS hardy
Fixed 2.0.0.19+nobinonly1-0ubuntu0.8.04.1
7.10 gutsy
Fixed 2.0.0.19+nobinonly1-0ubuntu0.7.10.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper
Not affected

Notes


kees

phishing filter bypass


jdstrand

per Mozilla, 2.0 only