CVE-2008-5505: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 3.0.5
Event History
Frequently Asked Questions
Which Firefox installations are affected?
Mozilla Firefox 3.x releases before 3.0.5 are affected. The issue is remotely exploitable and does not require authentication.
What does an attacker need to do to exploit this issue?
An attacker needs to cause a vulnerable Firefox user to process XUL containing a persist attribute. This can create and access data entities similar to cookies, bypassing intended privacy restrictions.
What is the recommended remediation?
Upgrade Firefox to version 3.0.5 or later. The provided information does not identify a workaround for systems that cannot be updated immediately.