Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Unpatched input validation flaw in Firefox
From: "Thor Larholm" <larholm () gmail com>
Date: Mon, 4 Jun 2007 21:42:05 +0200

Firefox contains a fix for a directory traversal vulnerability
that allowed you to read local files through the resource protocol.

However, the patch only partially fixed the vulnerability on Windows
systems and accidentally circumvents an existing input validation

The net result is that you can still read some local files on Windows
and all user accessible files on Linux/Unix/OS X, with all user
accessible files potentially readable as well on Windows through the
patch regression.



Thor Larholm

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Unpatched input validation flaw in Firefox Thor Larholm (Jun 04)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]