Vulnerability Description
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.19 |
| Mozilla | Seamonkey | >= 1.0, < 1.1.14 |
| Mozilla | Thunderbird | >= 2.0, < 2.0.0.19 |
| Canonical | Ubuntu Linux | 6.06 |
| Debian | Debian Linux | 4.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33184Third Party Advisory
- http://secunia.com/advisories/33188Third Party Advisory
- http://secunia.com/advisories/33189Third Party Advisory
- http://secunia.com/advisories/33203Third Party Advisory
- http://secunia.com/advisories/33204Third Party Advisory
- http://secunia.com/advisories/33205Third Party Advisory
- http://secunia.com/advisories/33216Third Party Advisory
- http://secunia.com/advisories/33231Third Party Advisory
- http://secunia.com/advisories/33232Third Party Advisory
- http://secunia.com/advisories/33408Third Party Advisory
- http://secunia.com/advisories/33415Third Party Advisory
- http://secunia.com/advisories/33421Third Party Advisory
- http://secunia.com/advisories/33433Third Party Advisory
- http://secunia.com/advisories/33434Third Party Advisory
- http://secunia.com/advisories/33523Third Party Advisory
FAQ
What is CVE-2008-5506?
CVE-2008-5506 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the brows...
How severe is CVE-2008-5506?
CVE-2008-5506 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5506?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Canonical Ubuntu Linux, Debian Debian Linux.