First published: Wed Feb 04 2009(Updated: )
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =3.0.4 | |
Firefox | =3.0.5 | |
Firefox | =3.0-beta2 | |
Firefox | =3.0.3 | |
Firefox | =3.0 | |
Firefox | =3.0.1 | |
Firefox | =3.0.2 | |
Firefox | =3.0-beta5 | |
Firefox | =3.0-alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0358 has a moderate severity rating due to its ability to expose sensitive information to local users.
To mitigate CVE-2009-0358, users should upgrade to Mozilla Firefox version 3.0.6 or later.
CVE-2009-0358 affects Mozilla Firefox versions 3.0 through 3.0.5, including beta and alpha versions.
CVE-2009-0358 allows local users to access sensitive information via the browser's back button or history list.
There is no official workaround for CVE-2009-0358, and the recommended action is to upgrade the browser.