FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5015

This CVE name corresponds to:

Entered Topic
2008-11-13 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5015
Phase Assigned(20081110)

Description

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

References

Source Reference
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=447579
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-51.html
FEDORA FEDORA-2008-9669
MANDRIVA MDVSA-2008:230
REDHAT RHSA-2008:0978
SUNALERT 256408
SUSE SUSE-SA:2008:055
UBUNTU USN-667-1
CERT TA08-319A
BID 32281
OVAL oval:org.mitre.oval:def:11063
SECTRACK 1021191
SECUNIA 34501
SECUNIA 32713
SECUNIA 32778
VUPEN ADV-2008-3146
SECUNIA 32721
SECUNIA 32695
VUPEN ADV-2009-0977