CVE-2007-5338

Publication date 21 October 2007

Last updated 17 July 2025


Ubuntu priority

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.

Status

Package Ubuntu Release Status
firefox 7.10 gutsy
Fixed 2.0.0.8+2nobinonly-0ubuntu1
7.04 feisty
Fixed 2.0.0.8+1nobinonly-0ubuntu1
6.10 edgy
Fixed 2.0.0.8+0dfsg-0ubuntu0.6.10
6.06 LTS dapper
Fixed 1.5.dfsg+1.5.0.14~prepatch071011b-0ubuntu1
mozilla-thunderbird 7.04 feisty
Fixed 1.5.0.13+1.5.0.14b-0ubuntu0.7.04
6.10 edgy
Fixed 1.5.0.13+1.5.0.14b-0ubuntu0.6.10
6.06 LTS dapper
Fixed 1.5.0.13+1.5.0.14b-0ubuntu0.6.06
thunderbird 7.10 gutsy
Fixed 2.0.0.8~pre071022+nobinonly-0ubuntu0.7.10

References

Related Ubuntu Security Notices (USN)

    • USN-536-1
    • Thunderbird vulnerabilities
    • 23 October 2007
    • USN-535-1
    • Firefox vulnerabilities
    • 22 October 2007

Other references