Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
BID:9330
Info
Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
| Bugtraq ID: | 9330 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2002 12:00AM |
| Updated: | Jun 30 2002 12:00AM |
| Credit: | Discovery credited to Stephen P. Morse. |
| Vulnerable: |
SCO Open Server 5.0.7 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 |
| Not Vulnerable: | |
Discussion
Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
A problem has been discovered in the behavior of the cookie handling in Mozilla. If similar path attributes exist in two separate cookies, it may be possible for a site to gain unauthorized access to cookies issued by another site in the same domain. The correct behavior is to restrict this type of access based both on domain and exact path attribute information.
A problem has been discovered in the behavior of the cookie handling in Mozilla. If similar path attributes exist in two separate cookies, it may be possible for a site to gain unauthorized access to cookies issued by another site in the same domain. The correct behavior is to restrict this type of access based both on domain and exact path attribute information.
Exploit / POC
Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
Solution:
This issue has been resolved in Mozilla versions later than 1.3.
SCO has released advisory SCOSA-2004.8 addressing this and other issues. Please see the referenced advisory for further information.
Mozilla Browser 1.0 RC2
Mozilla Browser 1.0
Mozilla Browser 1.0 RC1
Mozilla Browser 1.0.1
Mozilla Browser 1.0.2
Mozilla Browser 1.1
Mozilla Browser 1.1 Beta
Mozilla Browser 1.1 Alpha
Mozilla Browser 1.2
Mozilla Browser 1.2 Beta
Mozilla Browser 1.2 Alpha
SCO Open Server 5.0.7
Solution:
This issue has been resolved in Mozilla versions later than 1.3.
SCO has released advisory SCOSA-2004.8 addressing this and other issues. Please see the referenced advisory for further information.
Mozilla Browser 1.0 RC2
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.0
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.0 RC1
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.0.1
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.0.2
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.1
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.1 Beta
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.1 Alpha
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.2
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.2 Beta
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
Mozilla Browser 1.2 Alpha
-
Mozilla Mozilla 1.5
http://www.mozilla.org/download.html
SCO Open Server 5.0.7
-
SCO 507mp3_vol.tar
Read the Maintenance Pack 3 Release and Installation Notes atftp://ftp.sco.com/pub/openserver5/507/mp/mp3/osr507mp3.txt
ftp://ftp.sco.com/pub/openserver5/507/mp/mp3/507mp3_vol.tar
References
Mozilla URI Sub-Directory Arbitrary Cookie Access Vulnerability
References:
References: