|
|
Mozilla Firefox Code Execution and Security Bypass Vulnerabilities
|
Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to manipulate certain data, disclose sensitive information or compromise a vulnerable system.
The first issue is caused by an error when handling a SOCKS5 proxy reply containing an overly long DNS name, which could be exploited to corrupt subsequent data stream in the response.
The second vulnerability is caused by a spoofing issue when handling "window.open()" calls. For additional information, see : VUPEN/ADV-2009-2006
The third issue is caused by memory corruption errors in the JavaScript and browser engines when parsing malformed data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code.
The fourth vulnerability is related to a broken functionality due to the window's global object receiving an incorrect security wrapper on pages that had a "Link:" HTTP header when an add-on implementing a Content Policy in JavaScript was installed, which could allow arbitrary JavaScript execution with chrome privileges.
Mozilla Firefox versions 3.x
Upgrade to Mozilla Firefox version 3.5.2 or 3.0.13 :
http://www.mozilla.com/firefox/
http://www.vupen.com/english/advisories/2009/2142 http://www.mozilla.org/security/announce/2009/mfsa2009-38.html http://www.mozilla.org/security/announce/2009/mfsa2009-44.html http://www.mozilla.org/security/announce/2009/mfsa2009-45.html http://www.mozilla.org/security/announce/2009/mfsa2009-46.html
In-depth
Binary Analysis
 |
Available in customer area as part of
VUPEN Binary Analysis & Exploits Service and
VUPEN Vulnerability Notification Service Ultimate Feed Edition.
Private Exploit or PoC
 |
Available in customer area as part of
VUPEN Binary Analysis & Exploits Service and
VUPEN Vulnerability Notification Service Ultimate Feed Edition.
Vulnerabilities reported by Andrej Andolsek, Juan Pablo Lopez Yacubian, Lucas Adamski, Bob Clary, Tobias Markus, Wladimir Palant and moz_bug_r_a4.
2009-08-04 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|