Lucene search

K
mozillaMozilla FoundationMFSA2008-47
HistoryNov 12, 2008 - 12:00 a.m.

Information stealing via local shortcut files β€” Mozilla

2008-11-1200:00:00
Mozilla Foundation
www.mozilla.org
16

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.4%

Security researcher Liu Die Yu of TopsecTianRongXin reported that locally saved .url shortcut files could be used to read information stored in the local cache. An attacker could use this vulnerability to steal information from a victim’s browser cache if they were able to get the victim to download two separate files, a .url shortcut and a HTML file. Given the relative complexity of this attack, the severity of the issue was determined to be moderate.

Affected configurations

Vulners
Node
mozillafirefoxRange<2.0.0.18
OR
mozillafirefoxRange<3.0.4
OR
mozillaseamonkeyRange<1.1.13
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.4%