CVE-2009-0355: Medium severity Mozilla Firefox vulnerability
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0355?
CVE-2009-0355 has a moderate severity rating due to its potential to allow unauthorized access to local files.
How do I fix CVE-2009-0355?
The solution to fix CVE-2009-0355 involves updating Mozilla Firefox to version 3.0.6 or later.
What versions of Mozilla Firefox are affected by CVE-2009-0355?
CVE-2009-0355 affects all versions of Mozilla Firefox prior to 3.0.6.
Can CVE-2009-0355 be exploited remotely?
CVE-2009-0355 requires user assistance for exploitation, making it less critical in terms of remote attacks.
What problem does CVE-2009-0355 introduce for users?
CVE-2009-0355 allows malicious web content to potentially read arbitrary files on a user's machine through crafted input elements.