Bug 827831 (CVE-2012-1945) - CVE-2012-1945 Mozilla: Information disclosure though Windows file shares and shortcut files (MFSA 2012-37)
Summary: CVE-2012-1945 Mozilla: Information disclosure though Windows file shares and ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-1945
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 816119
TreeView+ depends on / blocked
 
Reported: 2012-06-03 08:39 UTC by Huzaifa S. Sidhpurwala
Modified: 2023-05-12 12:17 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-06-07 00:29:24 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:0710 0 normal SHIPPED_LIVE Critical: firefox security update 2012-06-06 00:55:44 UTC
Red Hat Product Errata RHSA-2012:0715 0 normal SHIPPED_LIVE Critical: thunderbird security update 2012-06-07 03:46:35 UTC

Description Huzaifa S. Sidhpurwala 2012-06-03 08:39:47 UTC
Security researcher Paul Stone reported an attack where an HTML page hosted on a Windows share and then loaded could then load Windows shortcut files (.lnk) in the same share. These shortcut files could then link to arbitrary locations on the local file system of the individual loading the HTML page. That page could show the contents of these linked files or directories from the local file system in an iframe, causing information disclosure.

This issue could potentially affect Linux machines with samba shares enabled.

Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-37.html

Comment 1 Murray McAllister 2012-06-05 03:28:11 UTC
Acknowledgements:

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges security researcher Paul Stone as the original
reporter.

Comment 2 errata-xmlrpc 2012-06-05 20:59:31 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2012:0710 https://rhn.redhat.com/errata/RHSA-2012-0710.html

Comment 3 errata-xmlrpc 2012-06-06 23:51:15 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 5

Via RHSA-2012:0715 https://rhn.redhat.com/errata/RHSA-2012-0715.html


Note You need to log in before you can comment on or make changes to this bug.