CVE-2008-5913
Publication date 20 January 2009
Last updated 24 July 2024
Ubuntu priority
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
xulrunner-1.9 | ||
xulrunner-1.9.1 | ||
xulrunner-1.9.2 | ||