Oval Definition:oval:org.mitre.oval:def:21861
Revision Date:2014-05-26Version:61
Title:ELSA-2009:0436: firefox security update (Critical)
Description:Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0652
CVE-2009-1302
CVE-2009-1303
CVE-2009-1304
CVE-2009-1305
CVE-2009-1306
CVE-2009-1307
CVE-2009-1308
CVE-2009-1309
CVE-2009-1310
CVE-2009-1311
CVE-2009-1312
ELSA-2009:0436-02
Platform(s):Oracle Linux 5
Product(s):firefox
xulrunner
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5
  • OR xulrunner is earlier than 0:1.9.0.9-1.el5
  • OR xulrunner-devel is earlier than 0:1.9.0.9-1.el5
  • OR firefox is earlier than 0:3.0.9-1.el5
  • BACK