CVE-2011-2999
Publication date 28 September 2011
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
firefox-3.5 | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1210-1
- Firefox and Xulrunner vulnerabilities
- 28 September 2011
- USN-1213-1
- Thunderbird vulnerabilities
- 28 September 2011
- USN-1222-1
- Firefox vulnerabilities
- 29 September 2011