CVE Vulnerabilities

CVE-2009-3274

Published: Sep 21, 2009 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.6 MODERATE
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 2.0 (including) 2.0 (including)
Firefox Mozilla 2.0.0.1 (including) 2.0.0.1 (including)
Firefox Mozilla 2.0.0.2 (including) 2.0.0.2 (including)
Firefox Mozilla 2.0.0.3 (including) 2.0.0.3 (including)
Firefox Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Firefox Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Firefox Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Firefox Mozilla 2.0.0.7 (including) 2.0.0.7 (including)
Firefox Mozilla 2.0.0.8 (including) 2.0.0.8 (including)
Firefox Mozilla 2.0.0.9 (including) 2.0.0.9 (including)
Firefox Mozilla 2.0.0.10 (including) 2.0.0.10 (including)
Firefox Mozilla 2.0.0.11 (including) 2.0.0.11 (including)
Firefox Mozilla 2.0.0.12 (including) 2.0.0.12 (including)
Firefox Mozilla 2.0.0.13 (including) 2.0.0.13 (including)
Firefox Mozilla 2.0.0.14 (including) 2.0.0.14 (including)
Firefox Mozilla 2.0.0.15 (including) 2.0.0.15 (including)
Firefox Mozilla 2.0.0.16 (including) 2.0.0.16 (including)
Firefox Mozilla 2.0.0.17 (including) 2.0.0.17 (including)
Firefox Mozilla 2.0.0.18 (including) 2.0.0.18 (including)
Firefox Mozilla 2.0.0.19 (including) 2.0.0.19 (including)
Firefox Mozilla 2.0.0.20 (including) 2.0.0.20 (including)
Firefox Mozilla 3.0 (including) 3.0 (including)
Firefox Mozilla 3.0.1 (including) 3.0.1 (including)
Firefox Mozilla 3.0.2 (including) 3.0.2 (including)
Firefox Mozilla 3.0.3 (including) 3.0.3 (including)
Firefox Mozilla 3.0.4 (including) 3.0.4 (including)
Firefox Mozilla 3.0.5 (including) 3.0.5 (including)
Firefox Mozilla 3.0.6 (including) 3.0.6 (including)
Firefox Mozilla 3.0.7 (including) 3.0.7 (including)
Firefox Mozilla 3.0.8 (including) 3.0.8 (including)
Firefox Mozilla 3.0.9 (including) 3.0.9 (including)
Firefox Mozilla 3.0.10 (including) 3.0.10 (including)
Firefox Mozilla 3.0.11 (including) 3.0.11 (including)
Firefox Mozilla 3.0.12 (including) 3.0.12 (including)
Firefox Mozilla 3.0.13 (including) 3.0.13 (including)
Firefox Mozilla 3.0.14 (including) 3.0.14 (including)
Firefox Mozilla 3.5 (including) 3.5 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)
Firefox Mozilla 3.6-a1 (including) 3.6-a1 (including)
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.47.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.15-3.el4 *
Red Hat Enterprise Linux 4 RedHat nspr-0:4.7.6-1.el4_8 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-50.el4_8 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.12-25.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.15-3.el5_4 *
Red Hat Enterprise Linux 5 RedHat nspr-0:4.7.6-1.el5_4 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.15-3.el5_4 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:2.0.0.24-2.el5_4 *
Firefox Ubuntu dapper *
Firefox Ubuntu hardy *
Firefox Ubuntu upstream *
Xulrunner Ubuntu hardy *
Xulrunner Ubuntu intrepid *
Xulrunner Ubuntu jaunty *
Xulrunner Ubuntu karmic *
Xulrunner Ubuntu upstream *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9 Ubuntu upstream *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *
Xulrunner-1.9.1 Ubuntu upstream *

References