CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Apr 26, 2007 |
| Mfsa2007 31 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Apr 26, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Apr 26, 2007 |
| Oracle_linux | — | Upgrade firefox-develUpgrade firefox | Oct 16, 2024 | Apr 26, 2007 |
| Suse | — | Upgrade seamonkeyUpgrade seamonkey-spellcheckerUpgrade mozilla-dom-inspectorUpgrade MozillaFirefoxUpgrade mozilla-ircUpgrade mozilla-mailUpgrade MozillaFirefox-translationsUpgrade mozilla-venkmanUpgrade mozilla-develUpgrade seamonkey-venkmanUpgrade mozilla-calendarUpgrade mozilla-huUpgrade mozilla-deatUpgrade suse-releaseUpgrade seamonkey-mailUpgrade seamonkey-dom-inspectorUpgrade mozilla-csUpgrade seamonkey-ircUpgrade mozilla | Feb 17, 2015 | Apr 26, 2007 |
| Ubuntu | — | Upgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Apr 26, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub