Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flock | Flock | 2.5.1 (including) | 2.5.1 (including) |
Firefox | Mozilla | 3.5.1 (including) | 3.5.1 (including) |
Seamonkey | Mozilla | 1.1.7 (including) | 1.1.7 (including) |
Seamonkey | Ubuntu | hardy | * |
Seamonkey | Ubuntu | intrepid | * |
Seamonkey | Ubuntu | jaunty | * |
Seamonkey | Ubuntu | karmic | * |
Seamonkey | Ubuntu | lucid | * |
Seamonkey | Ubuntu | maverick | * |
Seamonkey | Ubuntu | natty | * |
Seamonkey | Ubuntu | oneiric | * |
Xulrunner-1.9.1 | Ubuntu | upstream | * |