CVE-2002-0594: Medium severity Galeon Galeon Browser vulnerability
Published Jun 18, 2002
·Updated
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
Affected Software
10 affected components
Galeon Galeon Browser=1.2
Galeon Galeon Browser=1.2.1
Mozilla Mozilla=0.9.9
Mozilla Mozilla=1.0-rc1
Netscape Navigator=6.0
Netscape Navigator=6.01
Netscape Navigator=6.1
Netscape Navigator=6.2
Netscape Navigator=6.2.1
Netscape Navigator=6.2.2
Remediation
Patch Available
Event History
Jun 18, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0594?
CVE-2002-0594 is classified as a medium severity vulnerability.
2
How do I fix CVE-2002-0594?
The recommended fix for CVE-2002-0594 is to update to a later version of Netscape Navigator or Mozilla that is not affected by this vulnerability.
3
What does CVE-2002-0594 exploit?
CVE-2002-0594 exploits the ability to determine the existence of files on the client system via a LINK element in a CSS page causing an HTTP redirect.
4
Which products are affected by CVE-2002-0594?
CVE-2002-0594 affects Netscape Navigator 6.0 through 6.2.2 and Mozilla 1.0 RC1.
5
Can CVE-2002-0594 lead to unauthorized access?
Yes, CVE-2002-0594 can potentially lead to unauthorized access by exposing file on the client system.