Mozilla Foundation Security Advisory 2007-24

Unauthorized access to wyciwyg:// documents

Announced
July 17, 2007
Reporter
Michal Zalewski
Impact
High
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 2.0.0.5
  • SeaMonkey 1.1.3

Description

Michal Zalewski reported that it was possible to bypass the same-origin checks and read from cached (wyciwyg) documents. It is possible to access wyciwyg:// documents without proper same domain policy checks through the use of HTTP 302 redirects. This enables the attacker to steal sensitive data displayed on dynamically generated pages; perform cache poisoning; and execute own code or display own content with URL bar and SSL certificate data of the attacked page (URL spoofing++).

References