PT-2005-3191 · Mozilla+2 · Firefox+2
Published
2005-07-13
·
Updated
2017-10-11
·
CVE-2005-2262
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Firefox versions 1.0.3 through 1.0.4
Netscape version 8.0.2
Description:
The issue allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" context menu on an image URL that is really a javascript: URL with an eval statement. This can be exploited when the user is deceived into using the "Set as Background" context menu in Netscape.
Recommendations:
For Firefox versions 1.0.3 through 1.0.4, avoid using the "Set As Wallpaper" context menu on untrusted image URLs until a fix is available.
For Netscape version 8.0.2, avoid using the "Set as Background" context menu on untrusted image URLs until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Netscape
Red Hat