First published: Wed Apr 22 2009(Updated: )
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | ||
Firefox | =0.1 | |
Firefox | =0.9_rc | |
Firefox | =0.8 | |
Firefox | =2.0.0.12 | |
Firefox | =1.5-beta2 | |
Firefox | =3.0.7 | |
Firefox | =1.5.2 | |
Firefox | =1.5.0.6 | |
Firefox | =1.8 | |
Firefox | =2.0.0.2 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.4 | |
Firefox | =1.0.2 | |
Firefox | =3.0.4 | |
Firefox | =1.5-beta1 | |
Firefox | =3.0.5 | |
Firefox | =1.5 | |
Firefox | =0.9.1 | |
Firefox | =1.0.4 | |
Firefox | =2.0.0.7 | |
Firefox | =1.0.7 | |
Firefox | =2.0.0.9 | |
Firefox | =0.10.1 | |
Firefox | =0.9 | |
Firefox | =2.0.0.16 | |
Firefox | =3.0-beta2 | |
Firefox | =1.5.6 | |
Firefox | =2.0.0.17 | |
Firefox | =0.7 | |
Thunderbird | ||
Firefox | =2.0.0.15 | |
Firefox | =0.2 | |
Firefox | =0.3 | |
Firefox | =1.0 | |
Firefox | =3.0.3 | |
Firefox | =1.5.0.7 | |
Firefox | =2.0 | |
Firefox | =1.0.1 | |
Firefox | =2.0-beta1 | |
Firefox | =2.0.0.14 | |
Firefox | =0.6 | |
Firefox | =0.7.1 | |
Firefox | =3.0.6 | |
Firefox | =1.5.0.8 | |
Firefox | =1.0.6 | |
Firefox | =2.0.0.3 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.7 | |
Firefox | =1.5.0.12 | |
Firefox | =2.0.0.6 | |
Firefox | =3.0 | |
Firefox | =2.0.0.11 | |
Firefox | =1.5.0.2 | |
Firefox | =1.0.3 | |
Firefox | =3.0.1 | |
Firefox | =2.0.0.4 | |
Firefox | =0.5 | |
Firefox | =0.6.1 | |
Firefox | =1.5.1 | |
Firefox | =2.0.0.21 | |
Firefox | =0.9.3 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.18 | |
Firefox | =2.0-rc2 | |
Firefox | =2.0.0.1 | |
Firefox | =3.0.2 | |
Firefox | =1.5.5 | |
Firefox | =0.9.2 | |
Firefox | =1.0-preview_release | |
Firefox | =2.0-beta_1 | |
Firefox | =3.0beta5 | |
Firefox | =2.0.0.20 | |
Firefox | =2.0.0.8 | |
Firefox | <=3.0.8 | |
Firefox | =3.0-beta5 | |
Firefox | =0.9-rc | |
Firefox | =2.0.0.19 | |
Firefox | =1.5.8 | |
Firefox | =1.5.3 | |
Firefox | =0.4 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.1 | |
Firefox | =0.10 | |
Firefox | =1.0.5 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0-rc3 | |
Firefox | =3.0-alpha | |
Firefox | =1.0.6 | |
Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1307 has a severe impact as it allows attackers to bypass the Same Origin Policy.
To fix CVE-2009-1307, upgrade to Mozilla Firefox version 3.0.9 or later.
CVE-2009-1307 affects Mozilla Firefox, Thunderbird, and SeaMonkey prior to specified versions.
CVE-2009-1307 is a cross-origin resource sharing vulnerability related to improper Same Origin Policy implementation.
Yes, CVE-2009-1307 can potentially allow remote attackers to read or modify sensitive data.