Oval Definition:oval:com.ubuntu.trusty:def:20148638000
Revision Date:2015-01-14Version:1
Title:CVE-2014-8638 on Ubuntu 14.04 LTS (trusty) - medium.
Description:The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-8638
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND Package Information
  • The 'firefox' package in trusty was vulnerable but has been fixed (note: '35.0+build3-0ubuntu0.14.04.2').
  • OR The 'thunderbird' package in trusty was vulnerable but has been fixed (note: '1:31.4.0+build1-0ubuntu0.14.04.1').
  • BACK