>> Mozilla Suite/Firefox/Thunderbird Code Execution Vulnerabilities
Title : Mozilla Suite/Firefox/Thunderbird Code Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0296 CVE ID : CVE-2005-0399 - CVE-2005-0401 - CVE-2005-0402 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-03-23
Technical Description
Several vulnerabilities were identified in Mozilla Suite, Firefox and Thunderbird, which may be exploited by attackers to execute arbitrary commands or bypass certain security features.
- The first vulnerability is due to a heap overrun error when processing a Netscape-specific extension block in GIF images, which may be exploited to run arbitrary code on a vulnerable system via a web page or email message containing a specially crafted GIF image.
- The second flaw occurs if a user bookmarked a specially crafted page as a Firefox sidebar panel, which could be exploited to execute arbitrary programs by opening a privileged page and injecting javascript into it.
- The third issue occurs when handling specially crafted XUL files, and may be exploited to bypass the restriction on opening privileged XUL.