HTTP: Mozilla Firefox Shortcut Processing Information Disclosure

This signature detects attempts to exploit a known vulnerability against Mozilla Firefox. A successful attack can result in a information disclosure.

Extended Description

Mozilla Firefox is prone to an information-disclosure vulnerability when processing '.url' shortcut files in HTML elements. An attacker can exploit the issue to obtain sensitive information such as browser cache files, cookie data, or local filesystem details. Information harvested may aid in further attacks. NOTE: To exploit this issue, the attacker must trick a victim into saving a malicious HTML file to the local system and then following a malicious URI. Mozilla Firefox 3.0.1, 3.0.2, and 3.0.3 are reported vulnerable.

Affected Products

Nortel_networks self-service_mps_1000,Red_hat fedora

References

BugTraq: 31747

CVE: CVE-2008-4582

Short Name
HTTP:STC:MOZILLA:URL-SHRTCUT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2008-4582 Disclosure Firefox Information Mozilla Processing Shortcut bid:31747
Release Date
09/11/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Sun

Mozilla

Avaya

Slackware

Ubuntu

Nortel_networks

Debian

CVSS Score

4.3

Found a potential security threat?