CVE-2009-0358

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.
References
Link Resource
http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html
http://rhn.redhat.com/errata/RHSA-2009-0256.html
http://secunia.com/advisories/33799
http://secunia.com/advisories/33809
http://secunia.com/advisories/33831
http://secunia.com/advisories/33841
http://secunia.com/advisories/33846
http://secunia.com/advisories/33869
http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm
http://www.mandriva.com/security/advisories?name=MDVSA-2009:044
http://www.mozilla.org/security/announce/2009/mfsa2009-06.html Vendor Advisory
http://www.securityfocus.com/bid/33598
http://www.securitytracker.com/id?1021667
http://www.ubuntu.com/usn/usn-717-1
http://www.vupen.com/english/advisories/2009/0313
https://bugzilla.mozilla.org/show_bug.cgi?id=441751
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10610
https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html
http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html
http://rhn.redhat.com/errata/RHSA-2009-0256.html
http://secunia.com/advisories/33799
http://secunia.com/advisories/33809
http://secunia.com/advisories/33831
http://secunia.com/advisories/33841
http://secunia.com/advisories/33846
http://secunia.com/advisories/33869
http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm
http://www.mandriva.com/security/advisories?name=MDVSA-2009:044
http://www.mozilla.org/security/announce/2009/mfsa2009-06.html Vendor Advisory
http://www.securityfocus.com/bid/33598
http://www.securitytracker.com/id?1021667
http://www.ubuntu.com/usn/usn-717-1
http://www.vupen.com/english/advisories/2009/0313
https://bugzilla.mozilla.org/show_bug.cgi?id=441751
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10610
https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:59

Type Values Removed Values Added
References () http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx - () http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx -
References () http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html -
References () http://rhn.redhat.com/errata/RHSA-2009-0256.html - () http://rhn.redhat.com/errata/RHSA-2009-0256.html -
References () http://secunia.com/advisories/33799 - () http://secunia.com/advisories/33799 -
References () http://secunia.com/advisories/33809 - () http://secunia.com/advisories/33809 -
References () http://secunia.com/advisories/33831 - () http://secunia.com/advisories/33831 -
References () http://secunia.com/advisories/33841 - () http://secunia.com/advisories/33841 -
References () http://secunia.com/advisories/33846 - () http://secunia.com/advisories/33846 -
References () http://secunia.com/advisories/33869 - () http://secunia.com/advisories/33869 -
References () http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm - () http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:044 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:044 -
References () http://www.mozilla.org/security/announce/2009/mfsa2009-06.html - Vendor Advisory () http://www.mozilla.org/security/announce/2009/mfsa2009-06.html - Vendor Advisory
References () http://www.securityfocus.com/bid/33598 - () http://www.securityfocus.com/bid/33598 -
References () http://www.securitytracker.com/id?1021667 - () http://www.securitytracker.com/id?1021667 -
References () http://www.ubuntu.com/usn/usn-717-1 - () http://www.ubuntu.com/usn/usn-717-1 -
References () http://www.vupen.com/english/advisories/2009/0313 - () http://www.vupen.com/english/advisories/2009/0313 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=441751 - () https://bugzilla.mozilla.org/show_bug.cgi?id=441751 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10610 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10610 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html - () https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html -

Information

Published : 2009-02-04 19:30

Updated : 2024-11-21 00:59


NVD link : CVE-2009-0358

Mitre link : CVE-2009-0358

CVE.ORG link : CVE-2009-0358


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor