DSA-1951-1 firefox-sage -- insufficient input sanitisingID: oval:org.secpod.oval:def:600299 | Date: (C)2011-05-13 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that firefox-sage, a lightweight RSS and Atom feed reader for Firefox, does not sanitise the RSS feed information correctly, which makes it prone to a cross-site scripting and a cross-domain scripting attack. For the stable distribution , this problem has been fixed in version 1.4.2-0.1+lenny1. For the oldstable distribution , this problem has been fixed in version 1.3.6-4etch1. For the testing distribution and the unstable distribution , this problem has been fixed in version 1.4.3-3. We recommend that you upgrade your firefox-sage packages.
Platform: |
Debian 5.0 |
Debian 4.0 |