Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Mozilla Products Multiple Remote Command Execution and Cross Site Scripting Vulnerabilities

Title : Mozilla Products Multiple Remote Command Execution and Cross Site Scripting Vulnerabilities
VUPEN ID : VUPEN/ADV-2006-2998
CVE ID : CVE-2006-3113 - CVE-2006-3677 - CVE-2006-3801 - CVE-2006-3802 - CVE-2006-3803 - CVE-2006-3804 - CVE-2006-3805 - CVE-2006-3806 - CVE-2006-3807 - CVE-2006-3808 - CVE-2006-3809 - CVE-2006-3810 - CVE-2006-3811
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-07-26


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

Multiple vulnerabilities have been identified in Mozilla Firefox, SeaMonkey, and Thunderbird, which may be exploited by remote attackers to take complete control of an affected system, bypass security restrictions, or disclose sensitive information.

The first issue is due to an error where JavaScript references to "frame" or "window" objects are not properly cleared when the referenced content is deleted, which could be exploited by attackers to execute arbitrary commands via a malicious web page or email.

The second vulnerability is due to an error when assigning specially crafted values to the "window.navigator" object, which could be exploited by attackers to compromise a vulnerable system by tricking a user into visiting a malicious web page.

The third flaw is due to a memory corruption error when handling simultaneous XPCOM events, which could be exploited by attackers to execute arbitrary commands via a malicious web page or email.

The fourth flaw is due to an error when accessing native DOM methods, which could be exploited by remote attackers to gain unauthorized access to sensitive data (e.g. cookies).

The fifth issue is due to an error when deleting temporary variables being used in the creation of new Function objects, which could be exploited by attackers to compromise a vulnerable system via a malicious web page or email message.

The sixth vulnerability is due to a heap overflow error when processing a VCard attachment containing a malformed base64 field (e.g. photo), which could be exploited by attackers to execute arbitrary commands.

The seventh issue is due to an error when deleting temporary objects, which could be exploited by attackers to compromise a vulnerable system via a malicious web page or email message.

The eighth vulnerability is due to integer overflow errors when processing overly long strings passed to the "toSource()" methods, which could be exploited by attackers to execute arbitrary commands.

The ninth flaw is due to an error in the "Object()" constructor, which could be exploited by attackers to compromise a vulnerable system via a malicious web page or email message.

The tenth issue is due to a privilege escalation error when handling specially crafted Proxy AutoConfig (PAC) scripts, which could be exploited by remote attackers to bypass security restrictions.

The eleventh flaw is due to errors in the "UniversalBrowserRead" and "UniversalBrowserWrite" permissions, which could be exploited by malicious scripts to obtain elevated privileges and install arbitrary programs on a vulnerable system.

The twelfth vulnerability is due to an error when processing specially crafted "XPCNativeWrapper" objects, which could be exploited by malicious people to conduct cross site scripting attacks.

The thirteenth flaw is due to various memory corruption errors, which could be exploited by malicious people to compromise a vulnerable system via a malicious web page.

The fourteenth issue is due to an error when handling chrome URLs, which could be exploited by malicious people to execute arbitrary scripts with elevated privileges.

Affected Products

Mozilla Firefox version 1.5.0.4 and prior
Mozilla Thunderbird version 1.5.0.4 and prior
Mozilla SeaMonkey version 1.0.2 and prior

Solution

Upgrade to Firefox 1.5.0.5, SeaMonkey 1.0.3, and Thunderbird 1.5.0.5 :
http://www.mozilla.org/products/

References

http://www.vupen.com/english/advisories/2006/2998
http://www.mozilla.org/security/announce/2006/mfsa2006-56.html
http://www.mozilla.org/security/announce/2006/mfsa2006-55.html
http://www.mozilla.org/security/announce/2006/mfsa2006-54.html
http://www.mozilla.org/security/announce/2006/mfsa2006-53.html
http://www.mozilla.org/security/announce/2006/mfsa2006-52.html
http://www.mozilla.org/security/announce/2006/mfsa2006-51.html
http://www.mozilla.org/security/announce/2006/mfsa2006-50.html
http://www.mozilla.org/security/announce/2006/mfsa2006-49.html
http://www.mozilla.org/security/announce/2006/mfsa2006-48.html
http://www.mozilla.org/security/announce/2006/mfsa2006-47.html
http://www.mozilla.org/security/announce/2006/mfsa2006-46.html
http://www.mozilla.org/security/announce/2006/mfsa2006-45.html
http://www.mozilla.org/security/announce/2006/mfsa2006-44.html
http://www.zerodayinitiative.com/advisories/ZDI-06-025.html

Credits

Vulnerabilities reported by Thilo Girmann, ZDI, Secunia Research, Thor Larholm, H. D. Moore, Daniel Veditz, Igor Bukanov, shutdown, Georgi Guninski, moz_bug_r_a4, Boris Zbarsky, Darin Fisher, Daniel Veditz, Jesse Ruderman, and Martijn Wargers.

ChangeLog

2006-07-26 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy