Vulnerability Description
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.18 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
- http://secunia.com/advisories/32713Third Party Advisory
- http://secunia.com/advisories/32721Third Party Advisory
- http://secunia.com/advisories/32778Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1Broken Link
- http://ubuntu.com/usn/usn-667-1Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230Third Party Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-53.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0977.htmlThird Party Advisory
FAQ
What is CVE-2008-5019?
CVE-2008-5019 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and exec...
How severe is CVE-2008-5019?
CVE-2008-5019 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5019?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Debian Debian Linux, Canonical Ubuntu Linux.