CVE-2008-5513

NameCVE-2008-5513
DescriptionUnspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1707-1
NVD severitymedium (attack range: remote, user-initiated)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
iceweasel (PTS)squeeze, squeeze (security)3.5.16-20fixed
wheezy31.3.0esr-1~deb7u1fixed
wheezy (security)31.7.0esr-1~deb7u1fixed
jessie31.6.0esr-1fixed
jessie (security)31.7.0esr-1~deb8u1fixed
stretch, sid38.0.1-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceweaselsource(unstable)3.0.5-1medium
iceweaselsourceetch2.0.0.19-0etch1mediumDSA-1707-1

Search for package or bug name: Reporting problems