Package: iceweasel
Severity: important
Tags: security patch

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for iceweasel.

CVE-2007-5947[0]:
| The jar protocol handler in Mozilla Firefox retrieves the inner URL
| regardless of its MIME type, and considers HTML documents within a jar
| archive to have the same origin as the inner URL, which allows remote
| attackers to conduct cross-site scripting (XSS) attacks via a jar:
| URI.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

There is a patch on 
https://bugzilla.mozilla.org/show_bug.cgi?id=369814

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpbbQm2RwI3G.pgp
Description: PGP signature

Reply via email to