Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3352

Overview

Vulnerability Score 6.4 6.4
CVE Id CVE-2006-3352
Last Modified 05 Sep 2008 05:06:53
Published 05 Jul 2006 09:05:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-3352

Summary

** DISPUTED ** Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object. NOTE: this description was based on a report that has since been retracted by the original authors. The authors misinterpreted their test results. Other third parties also disputed the original report. Therefore, this is not a vulnerability. It is being assigned a candidate number to provide a clear indication of its status.

Vulnerable Systems

Application

  • Mozilla Firefox 0.10

  • Mozilla Firefox 0.10.1

  • Mozilla Firefox 0.8

  • Mozilla Firefox 0.9

  • Mozilla Firefox 0.9.1

  • Mozilla Firefox 0.9.2

  • Mozilla Firefox 0.9.3

  • Mozilla Firefox 1.0

  • Mozilla Firefox 1.0.1

  • Mozilla Firefox 1.0.2

  • Mozilla Firefox 1.0.3

  • Mozilla Firefox 1.0.4

  • Mozilla Firefox 1.0.5

  • Mozilla Firefox 1.0.6

  • Mozilla Firefox 1.0.7

  • Mozilla Firefox 1.0.8

  • Mozilla Firefox 1.5

  • Mozilla Firefox 1.5.0.1

  • Mozilla Firefox 1.5.0.2

  • Mozilla Firefox 1.5.0.3

  • Mozilla Firefox 1.5.0.4

  • Mozilla Firefox 1.5.1

  • Mozilla Firefox 1.5.2

  • Mozilla Firefox 1.5.3

  • Mozilla Firefox 2.0

  • Mozilla Firefox Preview Release


References

BID - 18734

BUGTRAQ - 20060704 Re: Browser bugs hit IE, Firefox today (SANS)

BUGTRAQ - 20060630 Re: Browser bugs hit IE, Firefox today (SANS)

BUGTRAQ - 20060630 RE: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)

BUGTRAQ - 20060630 ISC: Firefox immune to outerHTML flaw in MSIE [Was: Browser bugs hit IE, Firefox]

BUGTRAQ - 20060630 Re: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)

BUGTRAQ - 20060630 Browser bugs hit IE, Firefox today (SANS)

MISC - http://isc.sans.org/diary.php?storyid=1448


Last Updated: 27 May 2016 10:42:58