Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
BID:11166
Info
Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
| Bugtraq ID: | 11166 |
| Class: | Design Error |
| CVE: |
CVE-2004-0906 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 13 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Max <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Browser 1.7.6 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 Mozilla Browser 1.4.4 |
| Not Vulnerable: |
Mozilla Firefox Preview Release Mozilla Browser 1.7.3 Mozilla Browser 0.9.2 |
Discussion
Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
Mozilla Firefox is reported susceptible to an improper file permission vulnerability. This vulnerability is reported to exist only in the Linux archive as published by the Mozilla Foundation. If the browser is installed by package management software contained in many distributions of Linux, this vulnerability is likely not present.
This allows attackers with local interactive access to computers hosting installations of Firefox to overwrite binaries and scripts used by Firefox. This allows script, or code execution in the context of the user running the affected package.
If this method of installation is used to install a system-wide version of the browser by the superuser, then root-owned files are world writable, allowing for code execution in the context of any user utilizing the affected package.
The installation package from Mozilla.org for versions 0.9.x of Firefox for Linux is reported to contain this vulnerability.
Mozilla Firefox is reported susceptible to an improper file permission vulnerability. This vulnerability is reported to exist only in the Linux archive as published by the Mozilla Foundation. If the browser is installed by package management software contained in many distributions of Linux, this vulnerability is likely not present.
This allows attackers with local interactive access to computers hosting installations of Firefox to overwrite binaries and scripts used by Firefox. This allows script, or code execution in the context of the user running the affected package.
If this method of installation is used to install a system-wide version of the browser by the superuser, then root-owned files are world writable, allowing for code execution in the context of any user utilizing the affected package.
The installation package from Mozilla.org for versions 0.9.x of Firefox for Linux is reported to contain this vulnerability.
Exploit / POC
Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
Solution:
SGI has released an advisory 20050304-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
RedHat has released advisories RHSA-2005:323 and RHSA-2005:335 to address this issue. Please see the referenced advisories to obtain fix information.
The vendor has released an upgrade dealing with this issue.
RedHat Fedora Legacy has released advisory FLSA:152883 addressing this and other issues for RedHat Linux 7.3, 9 and for Fedora Core 1 and Core 2. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
SGI has released an advisory 20050304-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
RedHat has released advisories RHSA-2005:323 and RHSA-2005:335 to address this issue. Please see the referenced advisories to obtain fix information.
The vendor has released an upgrade dealing with this issue.
RedHat Fedora Legacy has released advisory FLSA:152883 addressing this and other issues for RedHat Linux 7.3, 9 and for Fedora Core 1 and Core 2. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Mozilla Firefox 0.9 rc
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.1
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.2
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.3
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
References
Mozilla Firefox XPInstall Default Installation File Permission Vulnerability
References:
References:
- Bugzilla Bug 231083 - wrong file permissions after installation (Daniel Koukola
) - Bugzilla Bug 235781 - XPInstall ignores user's umask when installing files (Andrew Schultz
) - RHSA-2005:323-10 Critical: mozilla security update (RedHat)
- RHSA-2005:335-07 Critical: mozilla security update (RedHat)
- Insecure file permissions in the Firefox browser for Linux >= v0.9 (Max
)