Vulnerability of Firefox: obtaining previously visited urls

Synthesis of the vulnerability 

An attacker can use an uri of type about:cache-entry to detect if user previously visited a web site.
Impacted products: Firefox.
Severity of this bulletin: 1/4.
Creation date: 23/02/2007.
Références of this threat: CVE-2007-1116, VIGILANCE-VUL-6585.

Description of the vulnerability 

The about:cache uri displays the memory and disk cache of Firefox browser. Every object stored in cache is accessed via an uri like "about:cache-entry".

An attacker can create a script using about:cache-entry in order to detect if an uri is in cache.

This vulnerability therefore permits an attacker to obtain url of last sites visited by the victim.
This threat impacts software or systems such as Firefox.

Our Vigil@nce team determined that the severity of this computer threat is low.

The trust level is of type confirmed by a trusted third party, with an origin of internet server.

A proof of concept or an attack tool is available, so your teams have to process this alert. An attacker with a technician ability can exploit this cybersecurity bulletin.

Solutions for this threat 

