First published: Sat Jan 29 2005(Updated: )
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | =0.6 | |
Mozilla Firefox | =1.7 | |
Firefox | =0.9 | |
Mozilla Firefox | =1.7.1 | |
Thunderbird | =0.7 | |
Mozilla Firefox | =1.7.2 | |
Mozilla Firefox | =1.7-rc3 | |
Thunderbird | =0.8 | |
Mozilla Firefox | =1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0142 is classified as a moderate severity vulnerability due to the risk of local users accessing sensitive data.
To fix CVE-2005-0142, upgrade to Firefox version 1.0 or later, Thunderbird version 1.0 or later, or Mozilla 1.7.5 or later.
CVE-2005-0142 affects Firefox versions before 1.0, Thunderbird versions before 1.0, and various versions of Mozilla 1.7.
The impact of CVE-2005-0142 is that it allows local users to read certain web content or attachments belonging to other users due to improper file permissions.
CVE-2005-0142 cannot be exploited remotely as it only affects local access permissions.