Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
BID:27950
Info
Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
| Bugtraq ID: | 27950 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2008 12:00AM |
| Updated: | Feb 25 2008 02:52PM |
| Credit: | Alex aka kuza55 discovered this issue. |
| Vulnerable: |
Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.12 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0.0.10 Mozilla Firefox 2.0.0.10 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
Mozilla Firefox is prone to a vulnerability that allows attackers to set cookies for certain domain extensions.
The browser does not have any security provisions to prevent cookies from being set for extensions with embedded dots. Attackers can leverage this issue to set cookies in a manner that could aid in other web-based attacks.
Mozilla Firefox 2.x is vulnerable; other versions may also be affected.
Mozilla Firefox is prone to a vulnerability that allows attackers to set cookies for certain domain extensions.
The browser does not have any security provisions to prevent cookies from being set for extensions with embedded dots. Attackers can leverage this issue to set cookies in a manner that could aid in other web-based attacks.
Mozilla Firefox 2.x is vulnerable; other versions may also be affected.
Exploit / POC
Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious document.
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious document.
Solution / Fix
Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Firefox Domain Extensions Insecure Cookie Access Vulnerability
References:
References:
- Understanding Cookie Security (Alex's Corner)
- Vendor Homepage (Mozilla Foundation)