Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4582
HistoryOct 15, 2008 - 12:00 a.m.

CVE-2008-4582

2008-10-1500:00:00
ubuntu.com
ubuntu.com
30

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

87.3%

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and
SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly
identify the context of Windows .url shortcut files, which allows
user-assisted remote attackers to bypass the Same Origin Policy and obtain
sensitive information via an HTML document that is directly accessible
through a filesystem, as demonstrated by documents in (1) local folders,
(2) Windows share folders, and (3) RAR archives, and as demonstrated by
IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory
and (b) about:cache?device=disk, a variant of CVE-2008-2810.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox<Β 1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1UNKNOWN
ubuntu7.10noarchfirefox<Β 2.0.0.18+nobinonly-0ubuntu0.7.10UNKNOWN
ubuntu8.04noarchfirefox<Β 2.0.0.19+nobinonly1-0ubuntu0.8.04.1UNKNOWN
ubuntu10.04noarchfirefox<Β 3.0.4+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu10.10noarchfirefox<Β 3.0.4+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu11.04noarchfirefox<Β 3.0.4+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.04noarchfirefox-3.0<Β 3.0.4+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.10noarchfirefox-3.0<Β 3.0.4+nobinonly-0ubuntu0.8.10.1UNKNOWN
ubuntu8.04noarchseamonkey<Β 1.1.15+nobinonly-0ubuntu0.8.04.2UNKNOWN
ubuntu8.10noarchseamonkey<Β 1.1.15+nobinonly-0ubuntu0.8.10.2UNKNOWN
Rows per page:
1-10 of 201

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

87.3%