FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5505

This CVE name corresponds to:

Entered Topic
2008-12-19 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5505
Phase Assigned(20081212)

Description

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

References

Source Reference
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=295994
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-63.html
MANDRIVA MDVSA-2008:245
REDHAT RHSA-2008:1036
SUNALERT 256408
UBUNTU USN-690-1
BID 32882
OVAL oval:org.mitre.oval:def:10443
SECTRACK 1021428
SECUNIA 33216
SECUNIA 33188
SECUNIA 33203
SECUNIA 34501
VUPEN ADV-2009-0977
XF firefox-xul-weak-security(47411)