CVE-2009-0358: Infoleak
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0358?
CVE-2009-0358 has a moderate severity rating due to its ability to expose sensitive information to local users.
How do I fix CVE-2009-0358?
To mitigate CVE-2009-0358, users should upgrade to Mozilla Firefox version 3.0.6 or later.
What versions of Mozilla Firefox are affected by CVE-2009-0358?
CVE-2009-0358 affects Mozilla Firefox versions 3.0 through 3.0.5, including beta and alpha versions.
What type of information can be exposed due to CVE-2009-0358?
CVE-2009-0358 allows local users to access sensitive information via the browser's back button or history list.
Is there a workaround for CVE-2009-0358 if I cannot update Firefox?
There is no official workaround for CVE-2009-0358, and the recommended action is to upgrade the browser.