CVE-2005-4685: Medium severity Mozilla Firefox vulnerability
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4685?
CVE-2005-4685 is considered a moderate severity vulnerability due to its potential for cookie hijacking.
How do I fix CVE-2005-4685?
To fix CVE-2005-4685, update your Mozilla or Firefox browser to a version that addresses this cookie handling issue.
What is the impact of CVE-2005-4685?
The impact of CVE-2005-4685 allows attackers to trick users into accepting cookies from unintended domains, potentially leading to session hijacking.
Which software versions are affected by CVE-2005-4685?
CVE-2005-4685 affects various versions of Mozilla and Firefox, including versions from 0.8 to 1.8-alpha4.
Are there workarounds for CVE-2005-4685?
One workaround for CVE-2005-4685 is to disable cookies or use alternative privacy-focused browsers until an update can be applied.