CVE-2008-3198

NameCVE-2008-3198
DescriptionMozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1614-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceweaselsourceetch2.0.0.16-0etch1DSA-1614-1
iceweaselsource(unstable)3.0.1-1low

Notes

http://www.mozilla.org/security/announce/2008/mfsa2008-35.html

Search for package or bug name: Reporting problems