PT-2002-1072 · Gnome+1 · Nautilus-Mozilla+3

Published

2002-08-28

·

Updated

2016-10-18

·

CVE-2002-1126

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nautilus-devel versions 1.0.4 nautilus versions 1.0.4 nautilus-mozilla versions 1.0.4 Mozilla versions 1.1 and earlier
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. In certain situations, when a new page is being loaded, the document referrer is set too quickly, allowing web pages to determine the next page being visited, including manually entered URLs, using the onunload handler.
Recommendations For nautilus-devel version 1.0.4, consider restricting access to the package until a patch is available. For nautilus version 1.0.4, consider restricting access to the package until a patch is available. For nautilus-mozilla version 1.0.4, consider restricting access to the package until a patch is available. For Mozilla versions 1.1 and earlier, consider disabling the onunload handler as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08167
BDU:2015-08168
BDU:2015-08169
CVE-2002-1126

Affected Products

Mozilla Firefox
Nautilus
Nautilus-Devel
Nautilus-Mozilla