Publication date 15 June 2009
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site’s context, by modifying an http page to include an https iframe that references a script file on an http site, related to “HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages.”
Package | Ubuntu Release | Status |
firefox | 10.10 maverick | Ignored |
10.04 LTS lucid | Ignored | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
seamonkey | 10.10 maverick | Ignored |
10.04 LTS lucid | Ignored | |
9.10 karmic | Ignored | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored | |
6.06 LTS dapper | Not in release | |
xulrunner | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Ignored | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9 | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9.1 | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
CVEs in Firefox are tracked in the xulrunner source packages. The mapping of xulrunner sources to firefox is: xulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS xulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS xulrunner-1.9: firefox-3.0 xulrunner-1.9.1: firefox-3.5 Ubuntu 6.06 LTS and 10.04 LTS uses the embedded xulrunner and not the system xulrunner-1.9.2, so it is tracked in the firefox source package.
as of 2011-04-11, no details. Marking as ignored.