CVE-2008-4582
Summary
| CVE | CVE-2008-4582 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-15 20:08:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Application | Mozilla | Firefox | 2.0 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.1 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.10 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.11 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.12 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.13 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.14 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.15 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.16 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.17 | All | All | All |
| Application | Mozilla | Firefox | 3.0.1 | All | All | All |
| Application | Mozilla | Firefox | 3.0.2 | All | All | All |
| Application | Mozilla | Firefox | 3.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian update for xulrunner - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Debian -- Security Information -- DSA-1696-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Not Applicable |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| 455311 – (CVE-2008-4582) [FIX]mid-autumn festival vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking |
| LIUDIEYU[0] Firefox Privacy Broken If Used to Open Web Page File | af854a3a-2127-422b-91ae-364da2661108 | liudieyu0.blog124.fc2.com | Broken Link |
| (Mozilla Issues Fix for SeaMonkey) Mozilla Firefox '.url' Windows Shortcut Files May Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-1669-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Debian update for iceweasel - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1671-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 8 Update: firefox-2.0.0.18-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Not Applicable |
| MFSA 2008-47: Information stealing via local shortcut files | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Mozilla Firefox '.url' Windows Shortcut Files May Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1697-1 iceape | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Mozilla Firefox 2 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Not Applicable |
| US-CERT Technical Cyber Security Alert TA08-319A -- Mozilla Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Debian update for iceape - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Fedora update for firefox and xulrunner - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| [SECURITY] Fedora 9 Update: xulrunner-1.9.0.4-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Not Applicable |
| Sun Solaris Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Debian update for icedove - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Mozilla Firefox '.url' Shortcut Processing Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Fedora update for firefox - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Firefox .url Shortcut File Information Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| Mozilla SeaMonkey Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Permissions Required, Third Party Advisory |
| USN-667-1: Firefox and xulrunner vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.