CVE Database
/

CVE-2008-4582

Back to search

CVE-2008-4582

Published: Oct 15, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-1697
vendor-advisory
x_refsource_DEBIAN
1021190
vdb-entry
x_refsource_SECTRACK
DSA-1671
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-9667
vendor-advisory
x_refsource_FEDORA
ADV-2009-0977
vdb-entry
x_refsource_VUPEN
32192
third-party-advisory
x_refsource_SECUNIA
1021212
vdb-entry
x_refsource_SECTRACK
DSA-1669
vendor-advisory
x_refsource_DEBIAN
32778
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-9669
vendor-advisory
x_refsource_FEDORA
33433
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2818
vdb-entry
x_refsource_VUPEN
256408
vendor-advisory
x_refsource_SUNALERT
4416
third-party-advisory
x_refsource_SREASON
32721
third-party-advisory
x_refsource_SECUNIA
TA08-319A
third-party-advisory
x_refsource_CERT
32853
third-party-advisory
x_refsource_SECUNIA
DSA-1696
vendor-advisory
x_refsource_DEBIAN
32693
third-party-advisory
x_refsource_SECUNIA
32845
third-party-advisory
x_refsource_SECUNIA
33434
third-party-advisory
x_refsource_SECUNIA
32684
third-party-advisory
x_refsource_SECUNIA
USN-667-1
vendor-advisory
x_refsource_UBUNTU
31747
vdb-entry
x_refsource_BID
32714
third-party-advisory
x_refsource_SECUNIA
31611
vdb-entry
x_refsource_BID
34501
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now