Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunnerUpgrade devhelpUpgrade firefoxUpgrade xulrunner-devel-unstableUpgrade devhelp-develUpgrade xulrunner-devel | Dec 1, 2016 | Jul 17, 2008 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Jul 17, 2008 |
| Mfsa2008 35 | — | Upgrade to Mozilla Firefox version 2.0.0.16Upgrade to Mozilla Firefox version 3.0.1 | Jun 14, 2012 | Jul 17, 2008 |
| Oracle_linux | — | Upgrade devhelpUpgrade firefoxUpgrade yelpUpgrade xulrunnerUpgrade devhelp-develUpgrade xulrunner-devel-unstableUpgrade nspluginwrapperUpgrade xulrunner-devel | Oct 16, 2024 | Jul 17, 2008 |
| Suse | — | Upgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade mozilla-xulrunner190-64bitUpgrade mozilla-xulrunner190-develUpgrade mozilla-xulrunner190-gnomevfsUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner190-translations-64bitUpgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozilla-xulrunner190Upgrade suse-releaseUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner190-translations-32bitUpgrade MozillaFirefox | Dec 12, 2013 | Jul 17, 2008 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade firefoxUpgrade firefox-3.0 | Nov 8, 2024 | Jul 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub