RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
BID:20294
Info
RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
| Bugtraq ID: | 20294 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2006 12:00AM |
| Updated: | Oct 03 2006 06:45PM |
| Credit: | Mischa Spiegelmock and Andrew Wbeelsoi are credited with discovering these vulnerabilities. |
| Vulnerable: |
Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Firefox 2.0 beta 1 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 |
| Not Vulnerable: | |
Discussion
RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
Mozilla Firefox is prone to multiple unspecified JavaScript vulnerabilities because the application fails to properly sanitize user-supplied input before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or execute arbitrary machine code in the context of the affected application.
Reportedly, about 30 undisclosed flaws exist.
Update (October 3, 2006): This BID is being retired because reports indicate that these issues are a hoax. The researchers responsible for disclosing these vulnerabilities have claimed that their original reports were incorrect. A remote denial-of-service vulnerability may possibly affect the browser, but this has not been confirmed. A new BID will be created if subsequent reports confirm the possibility of the potential denial-of-service issue. Please see the references for more information.
Mozilla Firefox is prone to multiple unspecified JavaScript vulnerabilities because the application fails to properly sanitize user-supplied input before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or execute arbitrary machine code in the context of the affected application.
Reportedly, about 30 undisclosed flaws exist.
Update (October 3, 2006): This BID is being retired because reports indicate that these issues are a hoax. The researchers responsible for disclosing these vulnerabilities have claimed that their original reports were incorrect. A remote denial-of-service vulnerability may possibly affect the browser, but this has not been confirmed. A new BID will be created if subsequent reports confirm the possibility of the potential denial-of-service issue. Please see the references for more information.
Exploit / POC
RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
References:
References:
- Firefox Vulnerability Claim Was A Joke (David Utter)
- Hackers claim zero-day flaw in Firefox (Joris Evers)
- Mozilla Firefox Home Page (Mozilla)
- Update: Possible Vulnerability Reported at Toorcon (Window Snyder)
- zero-day flaws in Firefox: about 30 unpatched Firefox flaws ([email protected])