CVE-2011-3670
Publication date 1 February 2012
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
seamonkey | ||
thunderbird | ||
xulrunner-1.9.2 | ||
xulrunner-2.0 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1353-1
- Xulrunnner vulnerabilities
- 8 February 2012
- USN-1350-1
- Thunderbird vulnerabilities
- 8 February 2012