Package: iceweasel
Version: 3.0.5-1
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for iceweasel.

CVE-2009-0253[0]:
| Mozilla Firefox 3.0.5 allows remote attackers to trick a user into
| visiting an arbitrary URL via an onclick action that moves a crafted
| element to the current mouse position, related to a "Status Bar
| Obfuscation" and "Clickjacking" attack.

I have no 2.x version available to test this so it might be 
that this works in 2.x as well.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0253
    http://security-tracker.debian.net/tracker/CVE-2009-0253

-- 
Nico Golde - http://www.ngolde.de - [email protected] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpWCBZUYBQnW.pgp
Description: PGP signature

Reply via email to