Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
BID:11194
Info
Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
| Bugtraq ID: | 11194 |
| Class: | Design Error |
| CVE: |
CVE-2004-0909 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this vulnerability is credited to Jesse Ruderman <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 |
| Not Vulnerable: |
Mozilla Firefox Preview Release Mozilla Browser 1.7.3 |
Discussion
Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
A vulnerability is reported in the Mozilla 'enablePrivilege' method. Because the argument data of a 'enablePrivilege' method is used as text in a prompt dialog if the user has not accessed the principal previously, it is possible to manipulate dialog contents.
A remote attacker may exploit this condition to influence a victim user into permitting a malicious script to run.
A vulnerability is reported in the Mozilla 'enablePrivilege' method. Because the argument data of a 'enablePrivilege' method is used as text in a prompt dialog if the user has not accessed the principal previously, it is possible to manipulate dialog contents.
A remote attacker may exploit this condition to influence a victim user into permitting a malicious script to run.
Exploit / POC
Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
A proof of concept is available at the following location:
http://bugzilla.mozilla.org/attachment.cgi?id=154932&action=view
A proof of concept is available at the following location:
http://bugzilla.mozilla.org/attachment.cgi?id=154932&action=view
Solution / Fix
Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
Solution:
This issue is addressed in Mozilla 1.7.3 and Firefox Preview Release:
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
For more information please see the referenced Gentoo Linux advisory.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Browser 1.7
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Solution:
This issue is addressed in Mozilla 1.7.3 and Firefox Preview Release:
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
Gentoo has released an advisory (GLSA 200409-26) to address various issues in Mozilla Browsers. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems.
emerge sync
emerge -pv your-version
emerge your-version
For more information please see the referenced Gentoo Linux advisory.
HP has released an advisory (SSRT4826) dealing with this issue for their Tru64 UNIX platform. Please see the referenced advisory for more information.
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Mozilla Firefox 0.9 rc
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.1
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.2
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Firefox 0.9.3
-
Mozilla Firefox Preview Release
http://www.mozilla.org/products/firefox/releases/0.10.html
Mozilla Browser 1.7
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7 rc3
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.1
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
Mozilla Browser 1.7.2
-
Mozilla Mozilla 1.7.3
http://www.mozilla.org/releases/
References
Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability
References:
References: