PT-2002-1070 · Mozilla+1 · Netscape+4
Publicado
2002-06-18
·
Atualizado
2008-09-05
·
CVE-2002-0594
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
nautilus-devel versions 1.0.4
nautilus versions 1.0.4
nautilus-mozilla versions 1.0.4
Netscape version 6
Mozilla versions prior to 1.0 RC1
Description
The issue allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. Exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations
For nautilus-devel version 1.0.4, update to a version that contains a fix for this issue.
For nautilus version 1.0.4, update to a version that contains a fix for this issue.
For nautilus-mozilla version 1.0.4, update to a version that contains a fix for this issue.
For Netscape version 6, update to a version that contains a fix for this issue.
For Mozilla versions prior to 1.0 RC1, update to version 1.0 RC1 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mozilla Firefox
Netscape
Nautilus
Nautilus-Devel
Nautilus-Mozilla