Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
BID:11177
Info
Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
| Bugtraq ID: | 11177 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0905 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2004 12:00AM |
| Updated: | Aug 05 2010 07:45PM |
| Credit: | Discovery of this vulnerability is credited to Jesse Ruderman <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 9.1 SuSE Linux 9 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 |
| Not Vulnerable: |
Mozilla Firefox 0.10 Mozilla Browser 1.7.3 |
Discussion
Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
Both Mozilla and Firefox are reported to be prone to a cross-domain scripting vulnerability. It is reported that URI links that are dragged from one browser window and dropped into another browser window will bypass the browser same-origin policy security checks.
Certain URI types may be employed by a malicious website in order to trigger this vulnerability. If successful, this attack will result in the execution of arbitrary script code in the context of a target domain.
Both Mozilla and Firefox are reported to be prone to a cross-domain scripting vulnerability. It is reported that URI links that are dragged from one browser window and dropped into another browser window will bypass the browser same-origin policy security checks.
Certain URI types may be employed by a malicious website in order to trigger this vulnerability. If successful, this attack will result in the execution of arbitrary script code in the context of a target domain.
Exploit / POC
Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
A proof of concept is available for the Firefox browser at the following location. It should be noted that Symantec does not guarantee the integrity of this example:
http://bugzilla.mozilla.org/attachment.cgi?id=152856&action=view
A proof of concept is available for the Firefox browser at the following location. It should be noted that Symantec does not guarantee the integrity of this example:
http://bugzilla.mozilla.org/attachment.cgi?id=152856&action=view
Solution / Fix
Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
Solution:
The vendor has reported that this vulnerability is addressed in Mozilla version 1.7.3 and Firefox version 0.10.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Browser 1.0 RC1
Mozilla Browser 1.0 RC2
Mozilla Browser 1.0
Mozilla Browser 1.0.1
Mozilla Browser 1.0.2
Mozilla Browser 1.1
Mozilla Browser 1.1 Alpha
Mozilla Browser 1.1 Beta
Mozilla Browser 1.2 Alpha
Mozilla Browser 1.2
Mozilla Browser 1.2 Beta
Mozilla Browser 1.2.1
Mozilla Browser 1.3
Mozilla Browser 1.3.1
Mozilla Browser 1.4 b
Mozilla Browser 1.4
Mozilla Browser 1.4 a
Mozilla Browser 1.4.1
Mozilla Browser 1.4.2
Mozilla Browser 1.5
Mozilla Browser 1.6
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
The vendor has reported that this vulnerability is addressed in Mozilla version 1.7.3 and Firefox version 0.10.
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
RedHat Linux has released advisory RHSA-2004:486-18 along with fixes to address this, and other issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information on obtaining fixes.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla Firefox 0.8
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Firefox 0.9
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Firefox 0.9 rc
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Firefox 0.9.1
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Firefox 0.9.2
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Firefox 0.9.3
-
Mozilla Firefox 0.10
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10/Firefox%2 0Setup%201.0PR.exe
Mozilla Browser 1.0 RC1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.0 RC2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.0
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.0.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.0.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.1 Alpha
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.1 Beta
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.2 Alpha
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.2 Beta
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.2.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/ -
RedHat galeon-1.2.13-0.9.2.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/galeon-1.2.13-0 .9.2.legacy.i386.rpm -
RedHat mozilla-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-1.4.3-0 .9.1.legacy.i386.rpm -
RedHat mozilla-chat-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-chat-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-devel-1 .4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-dom-ins pector-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-js-debu gger-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-mail-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-mail-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nspr-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-de vel-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nss-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-1.4 .3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-dev el-1.4.3-0.9.1.legacy.i386.rpm
Mozilla Browser 1.3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.3.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.4 b
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.4
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.4 a
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.4.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/ -
RedHat epiphany-1.0.4-2.4.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/epiphany-1.0.4- 2.4.legacy.i386.rpm -
RedHat mozilla-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.4.3-1 .fc1.1.legacy.i386.rpm -
RedHat mozilla-chat-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1 .4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-ins pector-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debu gger-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-mail-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nspr-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-de vel-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nss-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.4 .3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-dev el-1.4.3-1.fc1.1.legacy.i386.rpm
Mozilla Browser 1.4.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.5
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.6
-
Conectiva libnspr-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnspr-devel-1.7.3-27852U9 0_4cl.i386.rpm -
Conectiva libnspr-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnspr-devel-1.7.3-60868U 10_1cl.i386.rpm -
Conectiva libnspr4-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnspr4-1.7.3-27852U90_4cl .i386.rpm -
Conectiva libnspr4-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnspr4-1.7.3-60868U10_1c l.i386.rpm -
Conectiva libnss-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnss-devel-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva libnss-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnss-devel-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva libnss3-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnss3-1.7.3-27852U90_4cl. i386.rpm -
Conectiva libnss3-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnss3-1.7.3-60868U10_1cl .i386.rpm -
Conectiva mozilla-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-1.7.3-27852U90_4cl. i386.rpm -
Conectiva mozilla-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-1.7.3-60868U10_1cl .i386.rpm -
Conectiva mozilla-base-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-base-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva mozilla-base-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-base-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva mozilla-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-devel-1.7.3-27852U9 0_4cl.i386.rpm -
Conectiva mozilla-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-devel-1.7.3-60868U 10_1cl.i386.rpm -
Conectiva mozilla-dom-inspector-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-dom-inspector-1.7.3 -27852U90_4cl.i386.rpm -
Conectiva mozilla-dom-inspector-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-dom-inspector-1.7. 3-60868U10_1cl.i386.rpm -
Conectiva mozilla-irc-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-irc-1.7.3-27852U90_ 4cl.i386.rpm -
Conectiva mozilla-irc-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-irc-1.7.3-60868U10 _1cl.i386.rpm -
Conectiva mozilla-js-debugger-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-js-debugger-1.7.3-2 7852U90_4cl.i386.rpm -
Conectiva mozilla-js-debugger-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-js-debugger-1.7.3- 60868U10_1cl.i386.rpm -
Conectiva mozilla-mail-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-mail-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva mozilla-mail-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-mail-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva mozilla-psm-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-psm-1.7.3-27852U90_ 4cl.i386.rpm -
Conectiva mozilla-psm-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-psm-1.7.3-60868U10 _1cl.i386.rpm -
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
References
Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability
References:
References: