PT-2009-3018 · Mozilla+1 · Firefox+1

Moz_Bug_R_A4

·

Published

2009-02-04

·

Updated

2024-12-12

·

CVE-2009-0355

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.6
Description The issue allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element. This occurs because the nsSessionStore.js component in Mozilla Firefox does not block changes of INPUT elements to type="file" during tab restoration.
Recommendations For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue. As a temporary workaround, consider avoiding the restoration of tabs from untrusted sources until a patch is applied. Restrict access to file input elements to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0355
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:0256
RHSA-2009:0257
RHSA-2009:0258
RHSA-2009_0256
RHSA-2009_0257
RHSA-2009_0258

Affected Products

Firefox
Red Hat