FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2269

This CVE name corresponds to:

Entered Topic
2005-07-16 firefox & mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2269
Phase Assigned(20050713)

Description

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

References

Source Reference
MISC http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
CONFIRM http://www.mozilla.org/security/announce/mfsa2005-55.html
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=298892
DEBIAN DSA-810
FEDORA FLSA:160202
REDHAT RHSA-2005:586
REDHAT RHSA-2005:587
REDHAT RHSA-2005:601
SUSE SUSE-SA:2006:022
SUSE SUSE-SA:2005:045
SUSE SUSE-SR:2005:018
SUSE SUSE-SA:2006:004
CIAC P-252
BID 14242
OVAL oval:org.mitre.oval:def:9777
VUPEN ADV-2005-1075
OVAL oval:org.mitre.oval:def:100004
OVAL oval:org.mitre.oval:def:100005
OVAL oval:org.mitre.oval:def:100011
OVAL oval:org.mitre.oval:def:1258
OVAL oval:org.mitre.oval:def:729
SECUNIA 16043
SECUNIA 16059
SECUNIA 16044
SECUNIA 19823