You are currently viewing a snapshot of www.mozilla.org taken on April 21, 2008. Most of this content is highly out of date (some pages haven't been updated since the project began in 1998) and exists for historical purposes only. If there are any pages on this archive site that you think should be added back to www.mozilla.org, please file a bug.



You are here: Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.12) > MFSA 2008-05

Mozilla Foundation Security Advisory 2008-05

Title: Directory traversal via chrome: URI
Impact: High
Announced: February 7, 2008
Reporter: Gerry Eisenhaur
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 2.0.0.12
  Thunderbird 2.0.0.12
  SeaMonkey 1.1.8

Description

Gerry Eisenhaur reported the chrome: URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used "flat" packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.

Mozilla researcher moz_bug_r_a4 reported that this vulnerability could be used to steal the contents of the browser's sessionstore.js file, which contains session cookie data and information about currently open web pages.

Workaround

Disable "flat-packaged" add-ons until a version containing these fixes can be installed.

References