CVE-2008-5506

Impact:
Moderate
Public Date:
2008-12-16
Bugzilla:
476278: CVE-2008-5506 Firefox XMLHttpRequest 302 response disclosure

The MITRE CVE dictionary describes this issue as:

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."

Find out more about CVE-2008-5506 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) (thunderbird) RHSA-2009:0002 2009-01-07
Red Hat Enterprise Linux 5 (thunderbird) RHSA-2009:0002 2009-01-07
Red Hat Enterprise Linux 5 RHSA-2008:1036 2008-12-17
Red Hat Enterprise Linux 2.1 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 4 RHSA-2008:1036 2008-12-17
Red Hat Enterprise Linux 4 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 3 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 4 (thunderbird) RHSA-2009:0002 2009-01-07

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.