CVE-2007-0996

NameCVE-2007-0996
DescriptionThe child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1336-1
NVD severitymedium (attack range: remote)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceweaselsource(unstable)2.0.0.2+dfsg-1low
mozilla-firefoxsourcesarge1.0.4-2sarge17mediumDSA-1336-1
xulrunnersource(unstable)1.8.0.10-1low

Notes

MFSA-2007-02

Search for package or bug name: Reporting problems