Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=109536612321898&w=2 | mailing list |
http://secunia.com/advisories/12580/ | third party advisory |
http://securitytracker.com/id?1011331 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17415 | vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=252342 | |
http://kuza55.blogspot.com/2008/02/understanding-cookie-security.html | |
http://www.securityfocus.com/bid/11186 | vdb entry vendor advisory |