CVE-2009-4102

NameCVE-2009-4102
DescriptionSage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1951-1
Debian Bugs559267

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefox-sagesourceetch1.3.6-4etch1DSA-1951-1
firefox-sagesourcelenny1.4.2-0.1+lenny1DSA-1951-1
firefox-sagesource(unstable)1.4.3-4medium559267

Search for package or bug name: Reporting problems