Lucene search

K
mozillaMozilla FoundationMFSA2008-32
HistoryJul 01, 2008 - 12:00 a.m.

Remote site run as local file via Windows URL shortcut β€” Mozilla

2008-07-0100:00:00
Mozilla Foundation
www.mozilla.org
15

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

87.1%

Mozilla community member Geoff reported that URL shortcut files on Windows (for example, saved IE favorites) could be interpreted as if they were in the local file context when opened by Firefox, although the referenced remote content would be downloaded and displayed. Scripts loaded from the remote site would have access to all local file content in Firefox 2 if they were programmed to look for it.

Affected configurations

Vulners
Node
mozillafirefoxRange<2.0.0.15
OR
mozillaseamonkeyRange<1.1.10
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

87.1%