Name | CVE-2004-0718 |
Description | The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-775-1, DSA-777-1, DSA-810-1, DTSA-14-1, DTSA-7-1, DTSA-8-2 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mozilla | source | sarge | 2:1.7.8-1sarge2 | medium | DSA-810-1 | |
mozilla | source | etch | 2:1.7.8-1sarge2 | DTSA-14-1 | ||
mozilla | source | (unstable) | 2:1.7.10-1 | medium | ||
mozilla-firefox | source | sarge | 1.0.4-2sarge1 | medium | DSA-775-1 | |
mozilla-firefox | source | etch | 1.0.4-2sarge3 | medium | DTSA-8-2 | |
mozilla-firefox | source | (unstable) | 1.0.6-1 | medium |
This has been fixed in mozilla-firefox 0.8 and mozilla 1.6, but recent
upstream versions became vulnerable again, see
https://bugzilla.mozilla.org/show_bug.cgi?id=296850
and were fixed again, it got CVE-2005-1937 for the reversion