First published: Tue Feb 08 2005(Updated: )
Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0232 has a moderate severity level as it allows remote attackers to alter user configuration settings.
To fix CVE-2005-0232, users should upgrade to a later version of Firefox than 1.0.
Only users of Mozilla Firefox version 1.0 are affected by CVE-2005-0232.
The attack vector for CVE-2005-0232 involves a malicious plugin exploiting user interaction with the about:config site.
There are no specific workarounds for CVE-2005-0232 other than upgrading to a patched version of the browser.