CVE-2008-2933: Input Validation
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2933?
CVE-2008-2933 is considered a moderate severity vulnerability.
How do I fix CVE-2008-2933?
To fix CVE-2008-2933, upgrade to Mozilla Firefox version 2.0.0.16 or later, or version 3.0.1 or later.
What versions of Mozilla Firefox are affected by CVE-2008-2933?
CVE-2008-2933 affects Mozilla Firefox versions prior to 2.0.0.16 and 3.0.1, including multiple earlier versions.
What type of vulnerability is CVE-2008-2933?
CVE-2008-2933 is a command injection vulnerability that allows attackers to access local files through malformed URIs.
Can CVE-2008-2933 lead to remote code execution?
CVE-2008-2933 does not directly lead to remote code execution but allows attackers to manipulate local files.