[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-4582Date: (C)2008-10-15   (M)2024-02-09


Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1021190
SECTRACK-1021212
http://www.securityfocus.com/archive/1/497091/100/0/threaded
SUNALERT-256408
BID-31611
BID-31747
SECUNIA-32192
SECUNIA-32684
SECUNIA-32693
SECUNIA-32714
SECUNIA-32721
SECUNIA-32778
SECUNIA-32845
SECUNIA-32853
SECUNIA-33433
SECUNIA-33434
SECUNIA-34501
SREASON-4416
ADV-2008-2818
ADV-2009-0977
DSA-1669
DSA-1671
DSA-1696
DSA-1697
FEDORA-2008-9667
FEDORA-2008-9669
TA08-319A
USN-667-1
firefox-internet-shortcut-info-disclosure(45740)
http://liudieyu0.blog124.fc2.com/blog-entry-6.html
http://www.mozilla.org/security/announce/2008/mfsa2008-47.html
https://bugzilla.mozilla.org/show_bug.cgi?id=455311

CPE    46
cpe:/a:mozilla:seamonkey:1.0:alpha
cpe:/o:microsoft:windows
cpe:/o:canonical:ubuntu_linux:8.10
cpe:/a:mozilla:seamonkey:1.1
...
CWE    1
CWE-264
OVAL    6
oval:org.secpod.oval:def:600503
oval:org.mitre.oval:def:8021
oval:org.mitre.oval:def:8140
oval:org.secpod.oval:def:600264
...

© SecPod Technologies