PT-2008-6180 · Mozilla+1 · Firefox+1

Luke Bryan

·

Published

2008-11-13

·

Updated

2017-09-29

·

CVE-2008-5015

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.x before 3.0.4
Description The issue allows user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system. This occurs when a file: URI is accessed in the same tab from a chrome or privileged about: page, assigning chrome privileges to the file.
Recommendations For Mozilla Firefox versions 3.x before 3.0.4, update to version 3.0.4 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5015
RHSA-2008:0978
RHSA-2008_0978

Affected Products

Firefox
Red Hat