CVE-2007-3844

NameCVE-2007-3844
DescriptionMozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1344-1, DSA-1345-1, DSA-1346-1, DSA-1391-1, DTSA-51-1, DTSA-52-1, DTSA-53-1, DTSA-71-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icedove (PTS)jessie1:52.3.0-4~deb8u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceapesourceetch1.0.10~pre070720-0etch3DSA-1346-1
iceapesourcelenny1.0.10~pre070720-0etch3+lenny1DTSA-52-1
iceapesource(unstable)1.1.3-2medium
icedovesourceetch1.5.0.13+1.5.0.14b.dfsg1-0etch1DSA-1391-1
icedovesourcelenny1.5.0.13+1.5.0.14b.dfsg1-0lenny1DTSA-71-1
icedovesource(unstable)2.0.0.6-1medium
iceweaselsourceetch2.0.0.6-0etch1DSA-1344-1
iceweaselsourcelenny2.0.0.6-0etch1+lenny1DTSA-53-1
iceweaselsource(unstable)2.0.0.6-1medium
xulrunnersourceetch1.8.0.13~pre070720-0etch3DSA-1345-1
xulrunnersourcelenny1.8.0.13~pre070720-0etch3+lenny1DTSA-51-1
xulrunnersource(unstable)1.8.1.6-1medium

Notes

MFSA2007-26

Search for package or bug name: Reporting problems