PT-2008-6929 · Mozilla · Firefox+1

Publicado

1970-01-01

·

Atualizado

2018-10-30

·

CVE-2008-4582

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.0.1 through 3.0.3 Mozilla Firefox 2.x before 2.0.0.18 SeaMonkey 1.x before 1.1.13
Description The issue allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem. This can be demonstrated by documents in local folders, Windows share folders, and RAR archives, as well as by IFRAMEs referencing shortcuts that point to specific about:cache pages.
Recommendations For Mozilla Firefox versions 3.0.1 through 3.0.3, update to a version outside of this range to resolve the issue. For Mozilla Firefox 2.x before 2.0.0.18, update to version 2.0.0.18 or later to resolve the issue. For SeaMonkey 1.x before 1.1.13, update to version 1.1.13 or later to resolve the issue. As a temporary workaround, consider restricting access to HTML documents in local folders, Windows share folders, and RAR archives to minimize the risk of exploitation. Avoid using IFRAMEs that reference shortcuts pointing to about:cache?device=memory and about:cache?device=disk until the issue is resolved.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02788
BDU:2015-02789
BDU:2015-02790
BDU:2015-02791
BDU:2015-02792
BDU:2015-02793
BDU:2015-02794
BDU:2015-02795
BDU:2015-02796
BDU:2015-02797
CVE-2008-4582
DSA-1669-1
DSA-1671-1
DSA-1696-1
DSA-1697-1

Produtos afetados

Firefox
Seamonkey