PT-2008-6929 · Mozilla · Firefox+1

Published

1970-01-01

·

Updated

2018-10-30

·

CVE-2008-4582

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.0.1 through 3.0.3 Mozilla Firefox 2.x before 2.0.0.18 SeaMonkey 1.x before 1.1.13
Description The issue allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem. This can be demonstrated by documents in local folders, Windows share folders, and RAR archives, as well as by IFRAMEs referencing shortcuts that point to specific about:cache pages.
Recommendations For Mozilla Firefox versions 3.0.1 through 3.0.3, update to a version outside of this range to resolve the issue. For Mozilla Firefox 2.x before 2.0.0.18, update to version 2.0.0.18 or later to resolve the issue. For SeaMonkey 1.x before 1.1.13, update to version 1.1.13 or later to resolve the issue. As a temporary workaround, consider restricting access to HTML documents in local folders, Windows share folders, and RAR archives to minimize the risk of exploitation. Avoid using IFRAMEs that reference shortcuts pointing to about:cache?device=memory and about:cache?device=disk until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02788
BDU:2015-02789
BDU:2015-02790
BDU:2015-02791
BDU:2015-02792
BDU:2015-02793
BDU:2015-02794
BDU:2015-02795
BDU:2015-02796
BDU:2015-02797
CVE-2008-4582
DSA-1669-1
DSA-1671-1
DSA-1696-1
DSA-1697-1

Affected Products

Firefox
Seamonkey