Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Производитель ПО
Наименование ПО
Firefox
(2.0.0.1)
Описание
Mozilla Firefox не требует от пользователя подтверждения при сохранении закладок, что позволяет злоумышленникам, действующим удаленно, обойти ограничения политики доступа к домену, если пользователь сохранит в закладках страницу типа data: scheme, выполняющуюся в контексте последней открытой пользователем страницы.
Как исправить
Обновление не выпущено.
http://www.mozilla-europe.org/products/firefox/
http://www.mozilla-europe.org/products/firefox/
Ссылки
BUGTRAQ (20070221 Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/archive/1/460885/100/0/threaded
BUGTRAQ (20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/460890/100/0/threaded
BUGTRAQ (20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/460896/100/0/threaded
http://lcamtuf.coredump.cx/ffbook
https://bugzilla.mozilla.org/show_bug.cgi?id=371179
BID (22666): http://www.securityfocus.com/bid/22666
BUGTRAQ (20070222 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/archive/1/460896/100/0/threaded
BUGTRAQ (20070223 Re: [Full-disclosure] Firefox bookmark cross-domain surfingvulnerability): http://www.securityfocus.com/archive/1/archive/1/461021/100/0/threaded
http://lcamtuf.coredump.cx/ffbook/
http://www.heise-security.co.uk/news/85728
BUGTRAQ (20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/460890/100/0/threaded
BUGTRAQ (20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/460896/100/0/threaded
http://lcamtuf.coredump.cx/ffbook
https://bugzilla.mozilla.org/show_bug.cgi?id=371179
BID (22666): http://www.securityfocus.com/bid/22666
BUGTRAQ (20070222 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability): http://www.securityfocus.com/archive/1/archive/1/460896/100/0/threaded
BUGTRAQ (20070223 Re: [Full-disclosure] Firefox bookmark cross-domain surfingvulnerability): http://www.securityfocus.com/archive/1/archive/1/461021/100/0/threaded
http://lcamtuf.coredump.cx/ffbook/
http://www.heise-security.co.uk/news/85728