PT-2005-3191 · Mozilla+2 · Firefox+2

Published

2005-07-13

·

Updated

2017-10-11

·

CVE-2005-2262

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Firefox versions 1.0.3 through 1.0.4 Netscape version 8.0.2
Description: The issue allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" context menu on an image URL that is really a javascript: URL with an eval statement. This can be exploited when the user is deceived into using the "Set as Background" context menu in Netscape.
Recommendations: For Firefox versions 1.0.3 through 1.0.4, avoid using the "Set As Wallpaper" context menu on untrusted image URLs until a fix is available. For Netscape version 8.0.2, avoid using the "Set as Background" context menu on untrusted image URLs until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2262
DSA-779-1
DSA-779-2
DTSA-8-2
RHSA-2005:586
RHSA-2005_586

Affected Products

Firefox
Netscape
Red Hat