Summary
The remote host is missing an update to xulrunner
announced via advisory DSA 1873-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201873-1
Insight
Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid URLs could be used for spoofing the location bar and the SSL certificate status of a web page.
Xulrunner is no longer supported for the old stable distribution (etch).
For the stable distribution (lenny), this problem has been fixed in version 1.9.0.13-0lenny1.
For the unstable distribution (sid), this problem has been fixed in version 1.9.0.13-1.
We recommend that you upgrade your xulrunner packages.
Severity
Classification
-
CVE CVE-2009-2654 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities