Unpatched input validation flaw in Firefox 2.0.0.4

看板Bugtraq作者時間18年前 (2007/06/05 04:03), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Firefox 2.0.0.4 contains a fix for a directory traversal vulnerability that allowed you to read local files through the resource protocol. However, the patch only partially fixed the vulnerability on Windows systems and accidentally circumvents an existing input validation check. The net result is that you can still read some local files on Windows and all user accessible files on Linux/Unix/OS X, with all user accessible files potentially readable as well on Windows through the patch regression. http://larholm.com/2007/06/04/unpatched-input-validation-flaw-in-firefox-2004/ Cheers Thor Larholm
文章代碼(AID): #16P70100 (Bugtraq)