Name | CVE-2006-0299 |
Description | The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
Debian Bugs | 351442 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
firefox (PTS) | sid | 102.0-1 | fixed |
thunderbird (PTS) | stretch | 1:68.10.0-1~deb9u1 | fixed |
stretch (security) | 1:91.10.0-1~deb9u1 | fixed | |
buster | 1:78.14.0-1~deb10u1 | fixed | |
buster (security) | 1:91.10.0-1~deb10u1 | fixed | |
bullseye | 1:78.14.0-1~deb11u1 | fixed | |
bullseye (security) | 1:91.10.0-1~deb11u1 | fixed | |
bookworm, sid | 1:91.10.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
firefox | source | (unstable) | 1.5.dfsg+1.5.0.1-1 | 351442 | ||
mozilla | source | (unstable) | (not affected) | |||
mozilla-firefox | source | sarge | (not affected) | |||
mozilla-thunderbird | source | sarge | (not affected) | |||
thunderbird | source | (unstable) | 1.5.0.2-1 |
[sarge] - mozilla-firefox <not-affected> (Only Firefox 1.5 is affected)
- mozilla <not-affected> (E4X not implemented in Mozilla 1.7)
[sarge] - mozilla-thunderbird <not-affected> (Only 1.5 is affected)