PT-2009-3019 · Mozilla+1 · Firefox+2

Guninski

·

Published

2009-02-04

·

Updated

2024-12-12

·

CVE-2009-0356

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 3.0.6 SeaMonkey (affected versions not specified)
Description The issue allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges. This is achieved through vectors involving the URL field in a Desktop Entry section of a .desktop file, specifically by linking to the about:plugins and about:config URIs. The problem arises from the representation of about: URIs as jar:file:// URIs.
Recommendations For Mozilla Firefox versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue. For SeaMonkey, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0356
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:0256
RHSA-2009_0256

Affected Products

Firefox
Red Hat
Seamonkey