Lucene search

K
osvGoogleOSV:DSA-1873-1
HistoryAug 26, 2009 - 12:00 a.m.

xulrunner - spoofing vulnerabilities

2009-08-2600:00:00
Google
osv.dev
11

0.177 Low

EPSS

Percentile

96.2%

Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid
URLs could be used for spoofing the location bar and the SSL certificate
status of a web page.

Xulrunner is no longer supported for the old stable distribution (etch).

For the stable distribution (lenny), this problem has been fixed in
version 1.9.0.13-0lenny1.

For the unstable distribution (sid), this problem has been fixed in
version 1.9.0.13-1.

We recommend that you upgrade your xulrunner packages.