Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-2933
StatusCandidate
DescriptionMozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540.  NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
PhaseAssigned (30.06.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2933
ReferencesBID : 30242
 BUGTRAQ : 20080729 rPSA-2008-0238-1 firefox
 CERT-VN : VU#130923
 CONFIRM : http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0238
 CONFIRM : http://www.mozilla.org/security/announce/2008/mfsa...
 CONFIRM : http://www.novell.com/support/search.do?cmd=displa...
 CONFIRM : https://bugzilla.mozilla.org/show_bug.cgi?id=441120
 CONFIRM : https://issues.rpath.com/browse/RPL-2683
 DEBIAN : DSA-1614
 DEBIAN : DSA-1615
 DEBIAN : DSA-1697
 GENTOO : GLSA-200808-03
 MANDRIVA : MDVSA-2008:148
 OVAL : oval:org.mitre.oval:def:11618
 REDHAT : RHSA-2008:0597
 REDHAT : RHSA-2008:0598
 SECTRACK : 1020500
 SECUNIA : 31106
 SECUNIA : 31120
 SECUNIA : 31121
 SECUNIA : 31129
 SECUNIA : 31145
 SECUNIA : 31157
 SECUNIA : 31176
 SECUNIA : 31183
 SECUNIA : 31261
 SECUNIA : 31270
 SECUNIA : 31306
 SECUNIA : 31377
 SECUNIA : 33433
 SECUNIA : 34501
 SLACKWARE : SSA:2008-198-01
 SUNALERT : 256408
 UBUNTU : USN-623-1
 UBUNTU : USN-626-1
 UBUNTU : USN-626-2
 VUPEN : ADV-2009-0977
 XF : firefox-commandline-uri-security-bypass(43832)
SecurityVulns:Mozilla Firefox / Thunderbird / Seamonkey multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server