Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1669-1 | New xulrunner packages fix several vulnerabilities |
Debian DSA |
DSA-1671-1 | New iceweasel packages fix several vulnerabilities |
Debian DSA |
DSA-1696-1 | New icedove packages fix several vulnerabilities |
Debian DSA |
DSA-1697-1 | New iceape packages fix several vulnerabilities |
Ubuntu USN |
USN-667-1 | Firefox and xulrunner vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:24:19.339Z
Reserved: 2008-10-15T00:00:00
Link: CVE-2008-4582
No data.
Status : Deferred
Published: 2008-10-15T20:08:02.810
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4582
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN