PT-2008-2049 · Mozilla+1 · Firefox+1

Dolske

·

Published

2008-02-08

·

Updated

2024-12-12

·

CVE-2008-0417

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 2.0.0.12
Description A CRLF injection issue allows remote user-assisted web sites to corrupt the user's password store by not properly handling newlines when the user saves a password.
Recommendations For versions prior to 2.0.0.12, update to version 2.0.0.12 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0417
DSA-1484-1
DSA-1485-2
DSA-1489-1
DSA-1506-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2008:0103
RHSA-2008:0104
RHSA-2008_0103
RHSA-2008_0104

Affected Products

Firefox
Red Hat