Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
BID:17671
Info
Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
| Bugtraq ID: | 17671 |
| Class: | Design Error |
| CVE: |
CVE-2006-1993 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2006 12:00AM |
| Updated: | Sep 05 2007 02:11AM |
| Credit: | The vendor credits Martijn Wargers, Nick Mott with the discovery of this issue. <[email protected]> reported this issue as well. |
| Vulnerable: |
Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Mozilla Firefox 1.5.0.3 |
Discussion
Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
Mozilla Firefox is prone to a vulnerability when rendering malformed JavaScript content. An attacker could exploit this issue to cause the browser to fail or potentially execute arbitrary code.
Firefox versions 1.5 through to 1.5.0.2 running on Windows and Linux platforms are affected.
Mozilla Firefox is prone to a vulnerability when rendering malformed JavaScript content. An attacker could exploit this issue to cause the browser to fail or potentially execute arbitrary code.
Firefox versions 1.5 through to 1.5.0.2 running on Windows and Linux platforms are affected.
Exploit / POC
Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept examples can trigger a denial of service:
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept examples can trigger a denial of service:
Solution / Fix
Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue.
Please see the references for more information.
Mozilla Firefox 1.5.0.2
Mozilla Firefox 1.5.0.1
Mozilla Firefox 1.5.0.2
Mozilla Firefox 1.5 beta 2
Mozilla Firefox 1.5
Mozilla Firefox 1.5 beta 1
Solution:
The vendor has released an advisory along with fixes to address this issue.
Please see the references for more information.
Mozilla Firefox 1.5.0.2
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
Mozilla Firefox 1.5.0.1
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
Mozilla Firefox 1.5.0.2
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
Mozilla Firefox 1.5 beta 2
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
Mozilla Firefox 1.5
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
Mozilla Firefox 1.5 beta 1
-
Mozilla Firefox 1.5.0.3
http://www.mozilla.com/firefox/
References
Mozilla Firefox iframe.contentWindow.focus Deleted Object Reference Vulnerability
References:
References: