PT-2011-1285 · Mozilla · Firefox
Published
2011-08-09
·
Updated
2012-08-02
·
CVE-2008-7293
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 4
Description
The issue allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response. This is related to the lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, which can lead to a "cookie forcing" issue.
Recommendations
For versions prior to 4, update to version 4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox