Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
BID:13230
Info
Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
| Bugtraq ID: | 13230 |
| Class: | Design Error |
| CVE: |
CVE-2005-1154 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2005 12:00AM |
| Updated: | Feb 21 2007 06:36PM |
| Credit: | Shutdown is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SGI ProPack 3.0 SCO Unixware 7.1.4 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Netscape Navigator 7.2 Netscape Navigator 7.1 Netscape Navigator 7.0.2 Netscape Navigator 7.0 Netscape Collabra Server 3.5.2 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Browser 1.7.6 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 rc2 Mozilla Browser 1.7 rc1 Mozilla Browser 1.7 beta Mozilla Browser 1.7 alpha Mozilla Browser 1.7 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Firefox 1.0.3 Mozilla Browser 1.7.7 |
Discussion
Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
A remote cross-site scripting vulnerability affects Mozilla Suite and Mozilla Firefox because the software fails to properly clear stored parameters.
An attacker may exploit this issue to execute arbitrary script code in the context of a page that is currently being viewed. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Note that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
A remote cross-site scripting vulnerability affects Mozilla Suite and Mozilla Firefox because the software fails to properly clear stored parameters.
An attacker may exploit this issue to execute arbitrary script code in the context of a page that is currently being viewed. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Note that this issue was previously reported in BID 13208 (Mozilla Suite Multiple Code Execution, Cross-Site Scripting, And Policy Bypass Vulnerabilities); it has been assigned its own BID.
Exploit / POC
Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
Solution:
Mozilla has released and advisory along with upgrades dealing with this issue. Please see the references for more information.
Mozilla Firefox 0.10
Mozilla Firefox 0.10.1
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Firefox 1.0
Mozilla Firefox 1.0.1
Mozilla Firefox 1.0.2
Mozilla Browser 1.7 rc1
Mozilla Browser 1.7
Mozilla Browser 1.7 rc2
Mozilla Browser 1.7 alpha
Mozilla Browser 1.7 beta
Mozilla Browser 1.7 rc3
Mozilla Browser 1.7.1
Mozilla Browser 1.7.2
Mozilla Browser 1.7.3
Mozilla Browser 1.7.4
Mozilla Browser 1.7.5
Mozilla Browser 1.7.6
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
Solution:
Mozilla has released and advisory along with upgrades dealing with this issue. Please see the references for more information.
Mozilla Firefox 0.10
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.10.1
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.8
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9 rc
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 1.0
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 1.0.1
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/
Mozilla Firefox 1.0.2
-
Mozilla Firefox 1.0.3
http://www.mozilla.org/products/firefox/ -
Ubuntu mozilla-firefox-dev_1.0.2-0ubuntu5.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-dev_1.0.2-0ubuntu5.2_amd64.deb -
Ubuntu mozilla-firefox-dev_1.0.2-0ubuntu5.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-dev_1.0.2-0ubuntu5.2_i386.deb -
Ubuntu mozilla-firefox-dev_1.0.2-0ubuntu5.2_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-dev_1.0.2-0ubuntu5.2_ia64.deb -
Ubuntu mozilla-firefox-dev_1.0.2-0ubuntu5.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-dev_1.0.2-0ubuntu5.2_powerpc.deb -
Ubuntu mozilla-firefox-dom-inspector_1.0.2-0ubuntu5.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox/mozi lla-firefox-dom-inspector_1.0.2-0ubuntu5.2_amd64.deb -
Ubuntu mozilla-firefox-dom-inspector_1.0.2-0ubuntu5.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox/mozi lla-firefox-dom-inspector_1.0.2-0ubuntu5.2_i386.deb -
Ubuntu mozilla-firefox-dom-inspector_1.0.2-0ubuntu5.2_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox/mozi lla-firefox-dom-inspector_1.0.2-0ubuntu5.2_ia64.deb -
Ubuntu mozilla-firefox-dom-inspector_1.0.2-0ubuntu5.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/m/mozilla-firefox/mozi lla-firefox-dom-inspector_1.0.2-0ubuntu5.2_powerpc.deb -
Ubuntu mozilla-firefox-gnome-support_1.0.2-0ubuntu5.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-gnome-support_1.0.2-0ubuntu5.2_amd64.deb -
Ubuntu mozilla-firefox-gnome-support_1.0.2-0ubuntu5.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-gnome-support_1.0.2-0ubuntu5.2_i386.deb -
Ubuntu mozilla-firefox-gnome-support_1.0.2-0ubuntu5.2_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-gnome-support_1.0.2-0ubuntu5.2_ia64.deb -
Ubuntu mozilla-firefox-gnome-support_1.0.2-0ubuntu5.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox-gnome-support_1.0.2-0ubuntu5.2_powerpc.deb -
Ubuntu mozilla-firefox_1.0.2-0ubuntu5.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox_1.0.2-0ubuntu5.2_amd64.deb -
Ubuntu mozilla-firefox_1.0.2-0ubuntu5.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox_1.0.2-0ubuntu5.2_i386.deb -
Ubuntu mozilla-firefox_1.0.2-0ubuntu5.2_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox_1.0.2-0ubuntu5.2_ia64.deb -
Ubuntu mozilla-firefox_1.0.2-0ubuntu5.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/m/mozilla-firefox/mozilla- firefox_1.0.2-0ubuntu5.2_powerpc.deb
Mozilla Browser 1.7 rc1
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 rc2
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 alpha
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 beta
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7 rc3
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.1
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.2
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.3
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.4
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.5
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Mozilla Browser 1.7.6
-
Mozilla Suite 1.7.7
http://www.mozilla.org/products/mozilla1.x/
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
References
Mozilla Suite And Firefox Global Scope Pollution Cross-Site Scripting Vulnerability
References:
References:
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Foundation Security Advisory 2005-36 - Cross-site Scripting through (Mozilla)
- Mozilla Foundation Security Advisory 2005-37 - Code execution through javascrip (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- RHSA-2005:383-07 - firefox security update (RedHat)
- RHSA-2005:384-11 - Mozilla security update (Red Hat)
- RHSA-2005:386-08 - Mozilla security update (RedHat)
- Security Alerts (Netscape)
- Firelinking [Firefox 1.0.2] ("mikx"
)