CVE-2008-5024

Impact:
Low
Public Date:
2008-11-12
Bugzilla:
470902: CVE-2008-5024 Mozilla parsing error in E4X default namespace

The MITRE CVE dictionary describes this issue as:

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

Find out more about CVE-2008-5024 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 2.1 (seamonkey) RHSA-2008:0977 2008-11-13
Red Hat Enterprise Linux 3 (seamonkey) RHSA-2008:0977 2008-11-13
Red Hat Enterprise Linux 5 (thunderbird) RHSA-2008:0976 2008-11-20
Red Hat Enterprise Linux 5 RHSA-2008:0978 2008-11-13
Red Hat Enterprise Linux 4 RHSA-2008:0978 2008-11-13
Red Hat Enterprise Linux 4 (thunderbird) RHSA-2008:0976 2008-11-20
Red Hat Enterprise Linux 4 (seamonkey) RHSA-2008:0977 2008-11-13
Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) (thunderbird) RHSA-2008:0976 2008-11-20

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.