Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21304
HistoryFeb 05, 2009 - 12:00 a.m.

Mozilla Foundation Security Advisory 2009-06

2009-02-0500:00:00
vulners.com
21

Mozilla Foundation Security Advisory 2009-06

Title: Directives to not cache pages ignored
Impact: Low
Announced: February 3, 2009
Reporter: Paul Nel
Products: Firefox

Fixed in: Firefox 3.0.6
Description

Paul Nel reported that certain HTTP directives to not cache web pages, Cache-Control: no-store and Cache-Control: no-cache for HTTPS pages, were being ignored by Firefox 3. On a shared system, applications relying upon these HTTP directives could potentially expose private data. Another user on the system could use this vulnerability to view improperly cached pages containing private data by navigating the browser back.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=441751
* CVE-2009-0358