PT-2009-5588 · Mozilla+1 · Firefox+1

Jeremy Brown

·

Publicado

2009-09-21

·

Atualizado

2024-12-12

·

CVE-2009-3274

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions
Description The issue allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component.
Recommendations For Mozilla Firefox versions 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, consider restricting access to the /tmp directory to prevent exploitation. As a temporary workaround, consider disabling the Download Manager component until a patch is available. Avoid using the Downloads window to select files from untrusted sources until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-3274
DSA-1922-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:1530
RHSA-2009:1531
RHSA-2009_1530
RHSA-2009_1531
RHSA-2010:0153
RHSA-2010:0154
RHSA-2010_0153
RHSA-2010_0154

Produtos afetados

Firefox
Red Hat