Component for web browser writes an error message
to a known location, which can then be referenced by attackers to process
HTML/script in a less restrictive context
Potential Mitigations
ID
Phase
Description
Increase the entropy used to seed a PRNG.
2
Implementation
Perform FIPS 140-2 tests on data to catch obvious entropy
problems.
Other Notes
This is often a factor in attacks on web browsers, in which known or
predictable filenames become necessary to exploit browser
vulnerabilities.
Weakness Ordinalities
Ordinality
Description
Primary
(where the
weakness exists independent of other weaknesses)
Resultant
(where the
weakness is typically related to the presence of some other
weaknesses)