Mozilla Firefox Insecure Default Installation Vulnerability
BID:11644
Info
Mozilla Firefox Insecure Default Installation Vulnerability
| Bugtraq ID: | 11644 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 10 2004 12:00AM |
| Updated: | Nov 10 2004 12:00AM |
| Credit: | Reportedly this issue was discovered by Wolfgang Schwarz. |
| Vulnerable: |
Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 Mozilla Firefox 0.8 |
| Not Vulnerable: |
Mozilla Firefox 1.0 |
Discussion
Mozilla Firefox Insecure Default Installation Vulnerability
Mozilla Firefox is a Web browser developed and supported by the Mozilla Organization. It is freely available for most UNIX and Linux based operating systems as well as Microsoft Windows.
An insecure default installation vulnerability affects Mozilla Firefox. This issue is due to a failure of the application to place secure permissions on installed files. It should be noted that this issue only affects the vulnerable application installed on the Apple Mac OS X platform.
An unsuspecting user that double-clicks on such an affected application may have attacker-specified code executing with their privileges, potentially facilitating privilege escalation.
Mozilla Firefox is a Web browser developed and supported by the Mozilla Organization. It is freely available for most UNIX and Linux based operating systems as well as Microsoft Windows.
An insecure default installation vulnerability affects Mozilla Firefox. This issue is due to a failure of the application to place secure permissions on installed files. It should be noted that this issue only affects the vulnerable application installed on the Apple Mac OS X platform.
An unsuspecting user that double-clicks on such an affected application may have attacker-specified code executing with their privileges, potentially facilitating privilege escalation.
Exploit / POC
Mozilla Firefox Insecure Default Installation Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Mozilla Firefox Insecure Default Installation Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo has released an advisory GLSA 200501-03 to address various issues in multiple browsers offered by Mozilla. Gentoo users may carry out the following commands to update their computers:
Mozilla users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-1.7.5"
Mozilla binary users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-bin-1.7.5"
Firefox users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-1.0"
Firefox binary users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-bin-1.0"
Thunderbird users:
# emerge --sync
# emerge --ask --oneshot ?verbose ">=mail-client/mozilla-thunderbird-0.9"
Thunderbird:
# emerge --sync
# emerge --ask --oneshot ?verbose ">=mail-client/mozilla-thunderbird-bin-0.9"
Please see the referenced advisory for more information.
Mozilla Firefox 0.10
Mozilla Firefox 0.10.1
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Solution:
The vendor has released an upgrade dealing with this issue.
Gentoo has released an advisory GLSA 200501-03 to address various issues in multiple browsers offered by Mozilla. Gentoo users may carry out the following commands to update their computers:
Mozilla users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-1.7.5"
Mozilla binary users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-bin-1.7.5"
Firefox users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-1.0"
Firefox binary users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-bin-1.0"
Thunderbird users:
# emerge --sync
# emerge --ask --oneshot ?verbose ">=mail-client/mozilla-thunderbird-0.9"
Thunderbird:
# emerge --sync
# emerge --ask --oneshot ?verbose ">=mail-client/mozilla-thunderbird-bin-0.9"
Please see the referenced advisory for more information.
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.10.1
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0
http://www.mozilla.org/products/firefox/
References
Mozilla Firefox Insecure Default Installation Vulnerability
References:
References:
- Bugzilla Bug 261527 - OSX Default Install is insecure. (Mozilla)
- Mozilla Firefox Home Page (Mozilla)