Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
BID:14336
Info
Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
| Bugtraq ID: | 14336 |
| Class: | Design Error |
| CVE: |
CVE-2005-2455 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Mark Pilgrim <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Greasemonkey Greasemonkey 0.3.3 |
| Not Vulnerable: |
Greasemonkey Greasemonkey 0.3.5 |
Discussion
Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
Greasemonkey is susceptible to multiple remote information disclosure vulnerabilities. These issues are due to a design error allowing insecure JavaScript functions to be executed by remote Web sites.
The specified issues exist in the 'GM_xmlhttpRequest()', 'GM_setValue()', and 'GM_scripts()' functions.
Other GM_* functions also likely to be affected, but the exact functions are not known at this time.
These vulnerabilities allow remote attackers to retrieve the contents of arbitrary files, retrieve directory listings from arbitrary locations, and retrieve the contents of various private Greasemonkey data structures. This aids them in further attacks.
Greasemonkey is susceptible to multiple remote information disclosure vulnerabilities. These issues are due to a design error allowing insecure JavaScript functions to be executed by remote Web sites.
The specified issues exist in the 'GM_xmlhttpRequest()', 'GM_setValue()', and 'GM_scripts()' functions.
Other GM_* functions also likely to be affected, but the exact functions are not known at this time.
These vulnerabilities allow remote attackers to retrieve the contents of arbitrary files, retrieve directory listings from arbitrary locations, and retrieve the contents of various private Greasemonkey data structures. This aids them in further attacks.
Exploit / POC
Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
Proof of concept exploit Web pages have been provided at the following URIs. As these pages are provided by a third-party, Symantec cannot vouch for their content.
http://diveintogreasemonkey.org/experiments/function-leak.html
http://diveintogreasemonkey.org/experiments/script-leak.html
http://diveintogreasemonkey.org/experiments/xmlhttprequest-leak.html
http://diveintogreasemonkey.org/experiments/localfile-leak.html
Proof of concept exploit Web pages have been provided at the following URIs. As these pages are provided by a third-party, Symantec cannot vouch for their content.
http://diveintogreasemonkey.org/experiments/function-leak.html
http://diveintogreasemonkey.org/experiments/script-leak.html
http://diveintogreasemonkey.org/experiments/xmlhttprequest-leak.html
http://diveintogreasemonkey.org/experiments/localfile-leak.html
Solution / Fix
Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
Solution:
The vendor has released an updated version of the package to address these issues:
Greasemonkey Greasemonkey 0.3.3
Solution:
The vendor has released an updated version of the package to address these issues:
Greasemonkey Greasemonkey 0.3.3
-
Greasemonkey greasemonkey-0.3.5.xpi
http://atrus.org/hosted/greasemonkey-0.3.5.xpi
References
Greasemonkey Multiple Remote Information Disclosure Vulnerabilities
References:
References:
- Mandatory Greasemonkey Update (Greasemonkey)
- greasemonkey for secure data over insecure networks / sites (Greasemonkey)
- greasemonkey for secure data over insecure networks / sites (Greasemonkey)
- greasemonkey for secure data over insecure networks / sites (Greasemonkey)
- greasemonkey for secure data over insecure networks / sites (Greasemonkey)
- Greasemonkey Home Page (Greasemonkey)