PT-2009-3021 · Mozilla+1 · Firefox+1

Paul Nel

·

Published

2009-02-04

·

Updated

2024-12-12

·

CVE-2009-0358

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.x before 3.0.6
Description The issue allows local users to obtain sensitive information by using the back button or history list of the victim's browser. This can be demonstrated by reading the response page of an https POST request, indicating a problem with how Cache-Control directives are implemented.
Recommendations For Mozilla Firefox versions 3.x before 3.0.6, update to version 3.0.6 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0358
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2009:0256
RHSA-2009_0256

Affected Products

Firefox
Red Hat