Mozilla Firefox Resource Variant Directory Traversal Vulnerability

TITLE: Mozilla Firefox Resource Variant Directory Traversal Vulnerability
CLASS: Input Validation Error
CVE:
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 04 2007 12:00AM
UPDATE: Jun 04 2007 11:10PM
CREDIT: Thor Larholm is credited with the discovery of this issue.
VULNERABLE:

Mozilla Firefox 2.0 .4
NOT VULNERABLE:

Vai alla pagina originale su Security Focus

Discussion

Mozilla Firefox is prone to a directory-traversal vulnerability because it fails to adequately sanitize user-supplied data.

An attacker can exploit this issue to access arbitrary files on an unsuspecting user's computer. Successful exploits can expose potentially sensitive information that could aid in further attacks.

This issue was introduced as part of the fix for BID 24191 (Mozilla Firefox Resource Directory Traversal Vulnerability) in Firefox 2.0.0.4.

Exploit

To exploit this issue, an attacker must entice an unsuspecting user to visit a specially crafted webpage.

Solution

Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.

References

References:

PhpLog

BNLug Benevento Linux Users Group