CVE-2009-3985
Publication date 15 December 2009
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 10.04 LTS lucid |
Not affected
|
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
seamonkey | 10.04 LTS lucid |
Fixed 2.0.8+build1+nobinonly-0ubuntu0.10.04.1
|
9.10 karmic |
Fixed 2.0.8+build1+nobinonly-0ubuntu0.9.10.1
|
|
9.04 jaunty |
Fixed 2.0.8+build1+nobinonly-0ubuntu0.9.04.1
|
|
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy |
Fixed 2.0.8+build1+nobinonly-0ubuntu0.8.04.1
|
|
6.06 LTS dapper | Not in release | |
xulrunner-1.9 | 10.04 LTS lucid | Not in release |
9.10 karmic | Not in release | |
9.04 jaunty |
Fixed 1.9.0.16+nobinonly-0ubuntu0.9.04.1
|
|
8.10 intrepid |
Fixed 1.9.0.16+nobinonly-0ubuntu0.8.10.1
|
|
8.04 LTS hardy |
Fixed 1.9.0.16+nobinonly-0ubuntu0.8.04.1
|
|
6.06 LTS dapper | Not in release | |
xulrunner-1.9.1 | 10.04 LTS lucid | Not in release |
9.10 karmic |
Fixed 1.9.1.6+nobinonly-0ubuntu0.9.10.1
|
|
9.04 jaunty |
Fixed 1.9.1.6+nobinonly-0ubuntu0.9.04.1
|
|
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |