Skip to navigation

CVE Database

CVE-2007-0981

Impact: Moderate
Public: 2007-02-23
Bugzilla: 229253: CVE-2007-0981: seamonkey cookie setting / same-domain bypass vulnerability

Details

The MITRE CVE dictionary describes this issue as:

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

Find out more about CVE-2007-0981 from the MITRE CVE dictionary and NIST NVD.

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux Desktop version 5 (thunderbird) RHSA-2007:0108 March 14, 2007
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2007:0077 February 24, 2007
Red Hat Enterprise Linux version 3 (seamonkey) RHSA-2007:0077 February 24, 2007
Red Hat Enterprise Linux version 4 RHSA-2007:0077 February 24, 2007
Red Hat Enterprise Linux version 4 (firefox) RHSA-2007:0079 February 23, 2007
Red Hat Enterprise Linux version 4 (thunderbird) RHSA-2007:0078 March 02, 2007
Red Hat Enterprise Linux version 5 (firefox) RHSA-2007:0097 March 14, 2007

External References

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.