CVE-2007-3844

NameCVE-2007-3844
DescriptionMozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1344-1, DSA-1345-1, DSA-1346-1, DSA-1391-1, DTSA-51-1, DTSA-52-1, DTSA-53-1, DTSA-71-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icedove (PTS)wheezy31.8.0-1~deb7u1fixed
wheezy (security)38.7.0-1~deb7u1fixed
jessie31.8.0-1~deb8u1fixed
jessie (security)38.7.0-1~deb8u1fixed
stretch38.6.0-1fixed
sid38.7.2-1fixed
iceweasel (PTS)wheezy38.5.0esr-1~deb7u2fixed
wheezy (security)38.8.0esr-1~deb7u1fixed
jessie38.7.1esr-1~deb8u1fixed
jessie (security)38.8.0esr-1~deb8u1fixed
xulrunner (PTS)wheezy (security), wheezy24.8.1esr-2~deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceapesource(unstable)1.1.3-2medium
iceapesourceetch1.0.10~pre070720-0etch3mediumDSA-1346-1
iceapesourcelenny1.0.10~pre070720-0etch3+lenny1mediumDTSA-52-1
icedovesource(unstable)2.0.0.6-1medium
icedovesourceetch1.5.0.13+1.5.0.14b.dfsg1-0etch1mediumDSA-1391-1
icedovesourcelenny1.5.0.13+1.5.0.14b.dfsg1-0lenny1mediumDTSA-71-1
iceweaselsource(unstable)2.0.0.6-1medium
iceweaselsourceetch2.0.0.6-0etch1mediumDSA-1344-1
iceweaselsourcelenny2.0.0.6-0etch1+lenny1mediumDTSA-53-1
xulrunnersource(unstable)1.8.1.6-1medium
xulrunnersourceetch1.8.0.13~pre070720-0etch3mediumDSA-1345-1
xulrunnersourcelenny1.8.0.13~pre070720-0etch3+lenny1mediumDTSA-51-1

Notes

MFSA2007-26

Search for package or bug name: Reporting problems