Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Oct 21, 2007 |
| Mfsa2007 34 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Oct 21, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Oct 21, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Oct 21, 2007 |
| Suse | — | Upgrade mozilla-develUpgrade MozillaFirefoxUpgrade mozilla-venkmanUpgrade seamonkey-venkmanUpgrade mozilla-dom-inspectorUpgrade seamonkey-mailUpgrade MozillaFirefox-translationsUpgrade seamonkeyUpgrade mozilla-ircUpgrade mozilla-mailUpgrade seamonkey-spellcheckerUpgrade mozilla-calendarUpgrade mozillaUpgrade mozilla-deatUpgrade mozilla-csUpgrade seamonkey-ircUpgrade seamonkey-dom-inspectorUpgrade suse-releaseUpgrade mozilla-hu | Feb 17, 2015 | Oct 21, 2007 |
| Ubuntu | — | Upgrade mozilla-thunderbirdUpgrade firefox | Nov 8, 2024 | Oct 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub