CVE-2011-3000
Publication date 28 September 2011
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
firefox-3.5 | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1210-1
- Firefox and Xulrunner vulnerabilities
- 28 September 2011
- USN-1213-1
- Thunderbird vulnerabilities
- 28 September 2011
- USN-1222-1
- Firefox vulnerabilities
- 29 September 2011