CVE-2007-3844

NameCVE-2007-3844
DescriptionMozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1344-1, DSA-1345-1, DSA-1346-1, DSA-1391-1, DTSA-51-1, DTSA-52-1, DTSA-53-1, DTSA-71-1
NVD severitymedium (attack range: remote, user-initiated)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
iceape (PTS)squeeze (security)2.0.11-17fixed
icedove (PTS)squeeze, squeeze (security)3.0.11-1+squeeze15fixed
wheezy31.3.0-1~deb7u1fixed
wheezy (security)31.7.0-1~deb7u1fixed
jessie (security)31.7.0-1~deb8u1fixed
jessie, stretch31.6.0-1fixed
sid31.7.0-1fixed
iceweasel (PTS)squeeze, squeeze (security)3.5.16-20fixed
wheezy31.3.0esr-1~deb7u1fixed
wheezy (security)31.7.0esr-1~deb7u1fixed
jessie (security)31.7.0esr-1~deb8u1fixed
jessie, stretch31.6.0esr-1fixed
sid38.0.1-1fixed
xulrunner (PTS)wheezy, wheezy (security)24.8.1esr-2~deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceapesource(unstable)1.1.3-2medium
iceapesourceetch1.0.10~pre070720-0etch3mediumDSA-1346-1
iceapesourcelenny1.0.10~pre070720-0etch3+lenny1mediumDTSA-52-1
icedovesource(unstable)2.0.0.6-1medium
icedovesourceetch1.5.0.13+1.5.0.14b.dfsg1-0etch1mediumDSA-1391-1
icedovesourcelenny1.5.0.13+1.5.0.14b.dfsg1-0lenny1mediumDTSA-71-1
iceweaselsource(unstable)2.0.0.6-1medium
iceweaselsourceetch2.0.0.6-0etch1mediumDSA-1344-1
iceweaselsourcelenny2.0.0.6-0etch1+lenny1mediumDTSA-53-1
xulrunnersource(unstable)1.8.1.6-1medium
xulrunnersourceetch1.8.0.13~pre070720-0etch3mediumDSA-1345-1
xulrunnersourcelenny1.8.0.13~pre070720-0etch3+lenny1mediumDTSA-51-1

Notes

MFSA2007-26

Search for package or bug name: Reporting problems