CVE-2011-2362
Publication date 24 June 2011
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
firefox-3.5 | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1149-1
- Firefox and Xulrunner vulnerabilities
- 22 June 2011
- USN-1150-1
- Thunderbird vulnerabilities
- 15 July 2011