Mozilla Suite Multiple Remote Vulnerabilities
BID:12659
Info
Mozilla Suite Multiple Remote Vulnerabilities
| Bugtraq ID: | 12659 |
| Class: | Unknown |
| CVE: |
CVE-2005-0255 CVE-2005-0578 CVE-2005-0586 CVE-2005-0588 CVE-2005-0589 CVE-2005-0590 CVE-2005-0592 CVE-2005-0593 CVE-2005-0587 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2005 12:00AM |
| Updated: | Jan 25 2007 04:21PM |
| Credit: | Tavis Ormandy <[email protected]>, Andreas Sanblad, Masayuki Nakano (Mozilla Japan) <[email protected]>, Georgi Guninski <[email protected]>, Matt Brubeck Daniel de Wildt, Gaël Delalleau, Phil Ringnalda <[email protected]>, wind l |
| Vulnerable: |
SGI ProPack 3.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Mozilla Thunderbird 1.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Thunderbird 1.0.1 Mozilla Firefox 1.0.1 Mozilla Browser 1.7.6 |
Discussion
Mozilla Suite Multiple Remote Vulnerabilities
Multiple remote vulnerabilities affect Mozilla Suite, Firefox, and Thunderbird, as reported in several Mozilla Foundation Security Advisories:
- 2005-28: An issue affecting the plugin functionality; temporary directories are created in an insecure manner.
- 2005-22: A dialog-spoofing vulnerability.
- 2005-21: A '.lnk' link file arbitrary file-overwrite vulnerability.
- 2005-20: An XSLT stylesheet information-disclosure vulnerability.
- 2005-19: An information-disclosure issue affecting the form auto-complete functionality.
- 2005-18: A buffer-overflow vulnerability.
- 2005-17: A dialog-spoofing vulnerability affecting installation confirmation.
- 2005-15: A heap-overflow vulnerability in UTF8 encoding.
- 2005-15: Multiple spoofing vulnerabilities affecting the SSL 'secure site' lock icon.
An attacker may leverage these issues to spoof dialog boxes and SSL 'secure site' icons, to carry out symbolic-link attacks, to execute arbitrary code, and to access potentially sensitive information.
Please note that this BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed, at which time this 'umbrella' BID will be retired.
Multiple remote vulnerabilities affect Mozilla Suite, Firefox, and Thunderbird, as reported in several Mozilla Foundation Security Advisories:
- 2005-28: An issue affecting the plugin functionality; temporary directories are created in an insecure manner.
- 2005-22: A dialog-spoofing vulnerability.
- 2005-21: A '.lnk' link file arbitrary file-overwrite vulnerability.
- 2005-20: An XSLT stylesheet information-disclosure vulnerability.
- 2005-19: An information-disclosure issue affecting the form auto-complete functionality.
- 2005-18: A buffer-overflow vulnerability.
- 2005-17: A dialog-spoofing vulnerability affecting installation confirmation.
- 2005-15: A heap-overflow vulnerability in UTF8 encoding.
- 2005-15: Multiple spoofing vulnerabilities affecting the SSL 'secure site' lock icon.
An attacker may leverage these issues to spoof dialog boxes and SSL 'secure site' icons, to carry out symbolic-link attacks, to execute arbitrary code, and to access potentially sensitive information.
Please note that this BID will be separated into individual BIDs as soon as further research into each of the vulnerabilities is completed, at which time this 'umbrella' BID will be retired.
Exploit / POC
Mozilla Suite Multiple Remote Vulnerabilities
For most of these issues, an exploit is not required to carry out an attack. For the issues that require an exploit, we are currently unaware of any. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
For most of these issues, an exploit is not required to carry out an attack. For the issues that require an exploit, we are currently unaware of any. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Mozilla Suite Multiple Remote Vulnerabilities
Solution:
The vendor has released upgrades dealing with these issues. Mozilla has reported that a pending release of Mozilla Suite 1.7.6 will be released dealing with these issues in the near future. This BID will be updated upon release.
Please see the referenced advisories for further information.
Mozilla Firefox 0.10
Mozilla Firefox 0.10.1
Mozilla Thunderbird 0.6
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Thunderbird 0.8
Mozilla Firefox 0.9
Mozilla Thunderbird 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Firefox 1.0
Mozilla Thunderbird 1.0
Mozilla Browser 1.7
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Mozilla Browser 1.7.3
Mozilla Browser 1.7.4
Mozilla Browser 1.7.5
S.u.S.E. Linux Professional 10.0
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.3
Solution:
The vendor has released upgrades dealing with these issues. Mozilla has reported that a pending release of Mozilla Suite 1.7.6 will be released dealing with these issues in the near future. This BID will be updated upon release.
Please see the referenced advisories for further information.
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.10.1
-
Fedora firefox-1.0.1-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora firefox-1.0.1-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora firefox-debuginfo-1.0.1-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora firefox-debuginfo-1.0.1-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.6
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7.1
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.8
-
Fedora thunderbird-1.0.2-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-1.0.2-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-debuginfo-1.0.2-1.3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora thunderbird-debuginfo-1.0.2-1.3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Thunderbird 0.9
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Firefox 0.9 rc
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/
Mozilla Firefox 1.0
-
Mozilla Firefox 1.0.1
http://www.mozilla.org/products/firefox/ -
SuSE MozillaFirebird-1.0.1-2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/MozillaFirebird-1 .0.1-2.i586.rpm -
SuSE MozillaFirebird-1.0.1-2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/MozillaFirebi rd-1.0.1-2.x86_64.rpm -
SuSE MozillaFirefox-1.0.1-9.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaFirefox-1. 0.1-9.1.i586.rpm -
SuSE MozillaFirefox-1.0.1-9.1.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/MozillaFirefox-1. 0.1-9.1.i586.rpm -
SuSE MozillaFirefox-1.0.1-9.1.x86_64.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/MozillaFirefox- 1.0.1-9.1.x86_64.rpm -
SuSE MozillaFirefox-1.0.1-9.1.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaFirefo x-1.0.1-9.1.x86_64.rpm
Mozilla Thunderbird 1.0
-
Mozilla Thunderbird 1.0.1
http://www.mozilla.org/products/thunderbird/
Mozilla Browser 1.7
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.1
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.2
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.3
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.4
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.5
-
Mozilla Browser Suite 1.x
http://www.mozilla.org/products/mozilla1.x/
S.u.S.E. Linux Professional 10.0
-
SuSE MozillaFirefox-1.0.8-0.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/MozillaFirefox-1. 0.8-0.2.ppc.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/MozillaThunderbi rd-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/MozillaThunder bird-1.0.8-0.2.x86_64.rpm
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
S.u.S.E. Linux Professional 9.1
-
SuSE MozillaThunderbird-1.0.8-0.1.i586.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/MozillaThunderbir d-1.0.8-0.1.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.1.x86_64.rpm
SUSE LINUX 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/MozillaThunde rbird-1.0.8-0.1.x86_64.rpm
S.u.S.E. Linux Professional 9.2
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
S.u.S.E. Linux Professional 9.3
-
SuSE MozillaThunderbird-1.0.8-0.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/MozillaThunderbir d-1.0.8-0.2.i586.rpm -
SuSE MozillaThunderbird-1.0.8-0.2.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/MozillaThunderb ird-1.0.8-0.2.x86_64.rpm
References
Mozilla Suite Multiple Remote Vulnerabilities
References:
References:
- browser accepts dragged javascript: links (same-origin security hole) (Mozilla)
- Cisco NX-OS Download Page (Cisco)
- Firefox Release Notes (Mozilla)
- MFSA 2005-14: SSL "secure site" indicator spoofing (Mozilla)
- MFSA 2005-15: Heap overflow possible in UTF8 to Unicode conversion (Mozilla)
- MFSA 2005-17: Install source spoofing with user:pass@host (Mozilla)
- MFSA 2005-18: Memory overwrite in string library (Mozilla)
- MFSA 2005-19: Autocomplete data leak (Mozilla)
- MFSA 2005-20: XSLT can include stylesheets from arbitrary hosts (Mozilla)
- MFSA 2005-21: Overwrite arbitrary files downloading .lnk twice (Mozilla)
- MFSA 2005-22: Download dialog spoofing using Content-Disposition header (Mozilla)
- MFSA 2005-28: Unsafe /tmp/plugtmp directory exploitable to erase user's files (Mozilla)
- Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error (iDEFENSE)
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2005:277 Critical: mozilla security update (RedHat)
- RHSA-2005:337-02 Critical: thunderbird security update (RedHat)
- RHSA-2005:384-11 - Mozilla security update (Red Hat)
- Security Alerts (Netscape)