The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/461006/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/461013/100/0/threaded | mailing list |
http://osvdb.org/33804 | vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=371375 | patch vendor advisory |
http://www.gnucitizen.org/projects/hscan-redux/ | vendor advisory |
http://securityreason.com/securityalert/2309 | third party advisory |