CVE-2007-3074: Infoleak
Published Jun 6, 2007
·Updated
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.
Affected Software
5 affected components
Mozilla Firefox=2.0
Mozilla Firefox=2.0.0.1
Mozilla Firefox=2.0.0.2
Mozilla Firefox=2.0.0.3
Mozilla Firefox=2.0.0.4
Event History
Jun 6, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Which Firefox installations are affected?
Mozilla Firefox 2.0.0.4 and earlier are affected. The issue exposes files located in the local Firefox installation directory.
2
What does an attacker need to exploit this issue?
The attack can be performed remotely and does not require authentication. Exploitation has medium access complexity and relies on use of a resource:// URI.
3
What is the impact of successful exploitation?
A successful attacker can read files from the local Firefox installation directory. The provided impact metrics indicate confidentiality impact only, with no integrity or availability impact.