Oval Definition:oval:com.ubuntu.precise:def:20101585000
Revision Date:2010-04-28Version:1
Title:CVE-2010-1585 on Ubuntu 12.04 LTS (precise) - low.
Description:The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2010-1585
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'firefox' package in precise is not affected (note: '4.0~b12+build1+nobinonly-0ubuntu3').
  • OR NOT While related to the CVE in some way, the 'thunderbird' package in precise is not affected (note: '3.1.9+nobinonly-0ubuntu1').
  • BACK