CVE-2014-1591
Publication date 2 December 2014
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
14.04 LTS trusty |
Fixed 34.0+build2-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2424-1
- Firefox vulnerabilities
- 2 December 2014