CVE-2009-0355

NameCVE-2009-0355
Descriptioncomponents/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iceweaselsourceetch(unfixed)end-of-life
iceweaselsource(unstable)3.0.6-1

Notes

[etch] - iceweasel <end-of-life> (Etch Packages no longer covered by security support)

Search for package or bug name: Reporting problems