PT-2009-4304 · Mozilla+1 · Firefox+1

Adam Barth

+1

·

Publicado

2009-06-11

·

Atualizado

2017-09-29

·

CVE-2009-1839

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 3.0.11
Description: The issue allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document. This is achieved through a "file-URL-to-file-URL scripting" attack, where an incorrect principal is associated with a file: URL loaded through the location bar.
Recommendations: For versions prior to 3.0.11, update to version 3.0.11 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1839
DSA-1820-1
RHSA-2009:1095
RHSA-2009_1095

Produtos afetados

Firefox
Red Hat