Mozilla Firefox DATA URI File Deletion Vulnerability
BID:11311
Info
Mozilla Firefox DATA URI File Deletion Vulnerability
| Bugtraq ID: | 11311 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2004 12:00AM |
| Updated: | Oct 02 2004 12:00AM |
| Credit: | This vulnerability was reported to the vendor by Alex Vincent. |
| Vulnerable: |
Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release |
| Not Vulnerable: |
Mozilla Firefox 0.10.1 |
Discussion
Mozilla Firefox DATA URI File Deletion Vulnerability
It is reported that Mozilla Firefox is susceptible to a file deletion vulnerability.
This vulnerability allows attackers that can lure unsuspecting users to view malicious HTML or script code to cause the recursive deletion of the victim users configured download directory. They can achieve this by crafting malicious web pages containing either HTML or script code that utilizes the 'data:' URI scheme.
This vulnerability is reported to exist in Mozilla Firefox in versions prior to 0.10.1.
It is reported that Mozilla Firefox is susceptible to a file deletion vulnerability.
This vulnerability allows attackers that can lure unsuspecting users to view malicious HTML or script code to cause the recursive deletion of the victim users configured download directory. They can achieve this by crafting malicious web pages containing either HTML or script code that utilizes the 'data:' URI scheme.
This vulnerability is reported to exist in Mozilla Firefox in versions prior to 0.10.1.
Exploit / POC
Mozilla Firefox DATA URI File Deletion Vulnerability
An exploit is not required for this vulnerability.
An exploit is not required for this vulnerability.
Solution / Fix
Mozilla Firefox DATA URI File Deletion Vulnerability
Solution:
The vendor has released version 0.10.1 of Firefox, as well as a patch for Firefox Preview Release users addressing this issue:
Mozilla Firefox Preview Release
Mozilla Firefox 0.10
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Solution:
The vendor has released version 0.10.1 of Firefox, as well as a patch for Firefox Preview Release users addressing this issue:
Mozilla Firefox Preview Release
-
Mozilla 259708.xpi
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/patches /259708.xpi -
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.10
-
Mozilla 259708.xpi
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/patches /259708.xpi -
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.8
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.9
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.9 rc
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.9.1
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.9.2
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
Mozilla Firefox 0.9.3
-
Mozilla firefox-1.0PR-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.10.1/firefox -1.0PR-source.tar.bz2
References
Mozilla Firefox DATA URI File Deletion Vulnerability
References:
References:
- Bugzilla Bug 259708 - currently not public (Mozilla)
- Important Security Update for Firefox Available (Mozilla)
- Known Vulnerabilities in Mozilla (Mozilla)
- Mozilla Firefox Home Page (Mozilla)