First published: Wed Oct 15 2008(Updated: )
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Linux | =4.0 | |
Ubuntu | =6.06 | |
Ubuntu | =7.10 | |
Ubuntu | =8.04 | |
Ubuntu | =8.10 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0.3 | |
Microsoft Windows Operating System | ||
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0.0.11 | |
Firefox | =2.0.0.12 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.14 | |
Firefox | =2.0.0.15 | |
Firefox | =2.0.0.16 | |
Firefox | =2.0.0.17 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla SeaMonkey | =1.1.4 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.10 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla SeaMonkey | =1.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-4582 is classified as high due to the potential for exploitation of sensitive information.
To fix CVE-2008-4582, users should update to the latest versions of affected browsers, specifically Firefox 3.0.4 or later and SeaMonkey 1.1.13 or later.
CVE-2008-4582 affects Mozilla Firefox versions 3.0.1 to 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 on Windows.
Yes, CVE-2008-4582 can be exploited remotely if a user interacts with specially crafted files.
CVE-2008-4582 exploits the failure of affected browsers to properly handle context for .url shortcut files, bypassing the Same Origin Policy.