PT-2007-6406 · Mozilla+1 · Firefox+2

Published

2007-10-19

·

Updated

2018-10-15

·

CVE-2007-5337

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 2.0.0.8 SeaMonkey versions prior to 1.1.5
Description: The issue allows remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication. This is achieved by creating a web page on the target server, which contains URIs with smb: or sftp: schemes that access other files from the server.
Recommendations: For Mozilla Firefox versions prior to 2.0.0.8, update to version 2.0.0.8 or later. For SeaMonkey versions prior to 1.1.5, update to version 1.1.5 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5337
DSA-1392-1
DSA-1396-1
DSA-1401-1
DTSA-69-1
DTSA-80-1
HPSBUX02153
RHSA-2007:0979
RHSA-2007:0980
RHSA-2007:0981
RHSA-2007_0979
RHSA-2007_0980
RHSA-2007_0981

Affected Products

Firefox
Red Hat
Seamonkey