First published: Mon Feb 28 2005(Updated: )
The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =0.8 | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Firefox | =0.9 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =0.9.3 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Firefox | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0589 has been classified as a moderate severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2005-0589, users should update their Firefox browser to version 1.0.1 or later.
CVE-2005-0589 affects multiple versions of Mozilla Firefox prior to 1.0.1.
Attackers can exploit CVE-2005-0589 to steal potentially sensitive information captured through the autocomplete feature.
While upgrading to a patched version is recommended, disabling the autocomplete feature can serve as a temporary workaround for CVE-2005-0589.