CVE-2008-5507

Impact:
Moderate
Public Date:
2008-12-16
Bugzilla:
476280: CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message

The MITRE CVE dictionary describes this issue as:

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.

Find out more about CVE-2008-5507 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) (thunderbird) RHSA-2009:0002 2009-01-07
Red Hat Enterprise Linux 5 (thunderbird) RHSA-2009:0002 2009-01-07
Red Hat Enterprise Linux 5 RHSA-2008:1036 2008-12-17
Red Hat Enterprise Linux 2.1 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 4 RHSA-2008:1036 2008-12-17
Red Hat Enterprise Linux 4 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 3 (seamonkey) RHSA-2008:1037 2008-12-17
Red Hat Enterprise Linux 4 (thunderbird) RHSA-2009:0002 2009-01-07

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.