Lucene search

K
mozillaMozilla FoundationMFSA2008-35
HistoryJul 15, 2008 - 12:00 a.m.

Command-line URLs launch multiple tabs when Firefox not running — Mozilla

2008-07-1500:00:00
Mozilla Foundation
www.mozilla.org
22

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.012

Percentile

85.5%

Security researcher Billy Rios reported that if Firefox is not already running, passing it a command-line URI with pipe (“|”) symbols will open multiple tabs. This URI splitting could be used to launch chrome: URIs from the command-line, a partial bypass of the fix for MFSA 2005-53 which was intended to block external applications from loading such URIs (that vulnerability remains fixed, however).

Affected configurations

Vulners
Node
mozillafirefoxRange<2.0.0.16
OR
mozillafirefoxRange<3.0.1

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.012

Percentile

85.5%