CVE-2008-4582: Medium severity debian linux vulnerability
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4582?
The severity of CVE-2008-4582 is classified as high due to the potential for exploitation of sensitive information.
How do I fix CVE-2008-4582?
To fix CVE-2008-4582, users should update to the latest versions of affected browsers, specifically Firefox 3.0.4 or later and SeaMonkey 1.1.13 or later.
What software is affected by CVE-2008-4582?
CVE-2008-4582 affects Mozilla Firefox versions 3.0.1 to 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 on Windows.
Can CVE-2008-4582 be exploited remotely?
Yes, CVE-2008-4582 can be exploited remotely if a user interacts with specially crafted files.
What does CVE-2008-4582 exploit in Windows systems?
CVE-2008-4582 exploits the failure of affected browsers to properly handle context for .url shortcut files, bypassing the Same Origin Policy.