Mozilla Firefox Resource Variant Directory Traversal Vulnerability
TITLE: Mozilla Firefox Resource Variant Directory Traversal Vulnerability
CLASS: Input Validation Error
CVE:
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 04 2007 12:00AM
UPDATE: Jun 04 2007 11:10PM
CREDIT: Thor Larholm is credited with the discovery of this issue.
VULNERABLE:
Mozilla Firefox 2.0 .4NOT VULNERABLE:
Vai alla pagina originale su Security Focus
Discussion
Mozilla Firefox is prone to a directory-traversal vulnerability because it fails to adequately sanitize user-supplied data.
An attacker can exploit this issue to access arbitrary files on an unsuspecting user's computer. Successful exploits can expose potentially sensitive information that could aid in further attacks.
This issue was introduced as part of the fix for BID 24191 (Mozilla Firefox Resource Directory Traversal Vulnerability) in Firefox 2.0.0.4.
Exploit
To exploit this issue, an attacker must entice an unsuspecting user to visit a specially crafted webpage.
Solution
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.
References
References:
- Unpatched input validation flaw in Firefox 2.0.0.4 (Thor Larholm)
- Bug 367428 ??? resource:// directory traversal (Mozilla)
- Mozilla Homepage (Mozilla)
- Unpatched input validation flaw in Firefox 2.0.0.4 ("Thor Larholm"
)