Oval Definition:oval:org.opensuse.security:def:20085024
Revision Date:2022-06-30Version:1
Title:CVE-2008-5024
Description:

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2008-5024
Mitre CVE-2008-5024
SUSE CVE-2008-5024
openSUSE-SU-2014:1100-1
SUSE-SA:2008:055
Platform(s):Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
Open Enterprise Server
openSUSE 10.3
openSUSE 11.0
openSUSE Tumbleweed
SUSE Linux Enterprise SDK 10 SP2
Product(s):
Definition Synopsis
  • sles10-sp2-sdk is installed
  • AND gecko-sdk less than 1.8.0.14eol-0.9
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • MozillaThunderbird-91.1.1-1.1 is installed
  • OR MozillaThunderbird-translations-common-91.1.1-1.1 is installed
  • OR MozillaThunderbird-translations-other-91.1.1-1.1 is installed
  • BACK