PT-2005-3191 · Mozilla+2 · Firefox+2

Publicado

2005-07-13

·

Atualizado

2017-10-11

·

CVE-2005-2262

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Firefox versions 1.0.3 through 1.0.4 Netscape version 8.0.2
Description: The issue allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" context menu on an image URL that is really a javascript: URL with an eval statement. This can be exploited when the user is deceived into using the "Set as Background" context menu in Netscape.
Recommendations: For Firefox versions 1.0.3 through 1.0.4, avoid using the "Set As Wallpaper" context menu on untrusted image URLs until a fix is available. For Netscape version 8.0.2, avoid using the "Set as Background" context menu on untrusted image URLs until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2262
DSA-779-1
DSA-779-2
DTSA-8-2
RHSA-2005:586
RHSA-2005_586

Produtos afetados

Firefox
Netscape
Red Hat