CVE-2004-2228: High severity Mozilla Firefox vulnerability
Published Dec 31, 2004
·Updated
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
Affected Software
16 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=0.8
Mozilla Firefox=0.9.1
Mozilla Firefox=0.10.1
Mozilla Firefox=0.9
Mozilla Firefox=0.9.3
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.10
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2228?
CVE-2004-2228 is considered a high severity vulnerability due to the potential for local privilege escalation.
2
How do I fix CVE-2004-2228?
To fix CVE-2004-2228, users should upgrade to a version of Mozilla Firefox that is newer than 1.0.
3
Which versions of Mozilla Firefox are affected by CVE-2004-2228?
CVE-2004-2228 affects all Mozilla Firefox versions prior to 1.0, specifically versions 0.8 to 0.10.1.
4
What impact does CVE-2004-2228 have on Mac OS X users?
On Mac OS X, CVE-2004-2228 allows local users to gain elevated privileges through world-writable permissions.
5
Is CVE-2004-2228 unique to Mac OS X?
While CVE-2004-2228 specifically affects the Mac OS X platform, its underlying issue may be relevant in similar configurations on other operating systems.