Name | CVE-2009-4629 |
Description | Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests, as demonstrated by DNS requests triggered by reading text/plain e-mail messages in Thunderbird. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
iceape | source | etch | (not affected) | |||
iceape | source | lenny | (not affected) | |||
iceape | source | (unstable) | (unfixed) | unimportant | ||
icedove | source | etch | (not affected) | |||
icedove | source | lenny | (not affected) | |||
icedove | source | (unstable) | 3.0.2-1 | unimportant | ||
iceweasel | source | lenny | (not affected) | |||
iceweasel | source | (unstable) | 3.5.11-2 |
[etch] - icedove <not-affected> (dns prefetching implemented in xulrunner 1.9.1)
[lenny] - icedove <not-affected> (dns prefetching implemented in xulrunner 1.9.1)
[lenny] - iceweasel <not-affected> (Iceweasel in Lenny links against xulrunner)
[etch] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1)
[lenny] - iceape <not-affected> (dns prefetching implemented in xulrunner 1.9.1)