Mozilla Firefox OnKeyDown Event File Upload Vulnerability
BID:24725
Info
Mozilla Firefox OnKeyDown Event File Upload Vulnerability
| Bugtraq ID: | 24725 |
| Class: | Design Error |
| CVE: |
CVE-2007-3511 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2007 12:00AM |
| Updated: | Mar 18 2008 05:20PM |
| Credit: | Carl Hardwick <[email protected]> discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Sun Solaris 10_x86 Sun Solaris 10 Slackware Linux 10.2 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 10.SP1 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora Core6 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Mozilla SeaMonkey 1.1.4 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla SeaMonkey 1.0.99 Mozilla SeaMonkey 1.0.9 Mozilla SeaMonkey 1.0.8 Mozilla SeaMonkey 1.0.7 Mozilla SeaMonkey 1.0.6 Mozilla SeaMonkey 1.0.5 Mozilla SeaMonkey 1.0.3 Mozilla SeaMonkey 1.0.2 Mozilla SeaMonkey 1.0.1 Mozilla SeaMonkey 1.1 beta Mozilla SeaMonkey 1.0 dev Mozilla SeaMonkey 1.0 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .1 Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 12 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Firefox 1.5.0.9 Mozilla Firefox 1.5.0.8 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.11 Mozilla Firefox 1.5.0.10 Mozilla Firefox 1.5.0.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Debian Iceweasel 0 Debian Iceape 1.0.11 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: |
Mozilla SeaMonkey 1.1.5 Mozilla Firefox 2.0 .8 |
Discussion
Mozilla Firefox OnKeyDown Event File Upload Vulnerability
Mozilla Firefox is prone to an information-disclosure vulnerability that can allow an attacker to access sensitive files.
This issue stems from a design error resulting from the improper handling of form fields.
All versions of Firefox are considered vulnerable.
Mozilla Firefox is prone to an information-disclosure vulnerability that can allow an attacker to access sensitive files.
This issue stems from a design error resulting from the improper handling of form fields.
All versions of Firefox are considered vulnerable.
Exploit / POC
Mozilla Firefox OnKeyDown Event File Upload Vulnerability
A proof of concept is available at the following location:
http://yathong.googlepages.com/FirefoxFocusBug.html
A proof of concept is available at the following location:
http://yathong.googlepages.com/FirefoxFocusBug.html
Solution / Fix
Mozilla Firefox OnKeyDown Event File Upload Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Mozilla Firefox 1.5.0.3
Mozilla Firefox 1.5.0.2
Mozilla Firefox 2.0 RC2
Mozilla Firefox 1.5.0.1
Mozilla Firefox 1.5.0.7
Mozilla SeaMonkey 1.1 beta
Mozilla Firefox 1.5.0.6
Mozilla Firefox 2.0.0.2
Mozilla SeaMonkey 1.0 dev
Mozilla SeaMonkey 1.0
Mozilla Firefox 1.5.0.4
Slackware Linux 11.0
Slackware Linux 12.0
Slackware Linux -current
Mozilla SeaMonkey 1.0.1
Mozilla SeaMonkey 1.0.2
Mozilla SeaMonkey 1.0.5
Mozilla SeaMonkey 1.0.6
Mozilla SeaMonkey 1.0.7
Mozilla SeaMonkey 1.0.9
Mozilla SeaMonkey 1.0.99
Mozilla SeaMonkey 1.1.1
Mozilla Firefox 1.5 12
Mozilla Firefox 1.5 .8
Mozilla Firefox 1.5 beta 2
Slackware Linux 10.2
Mozilla Firefox 2.0 .1
Mozilla Firefox 2.0 .5
Mozilla Firefox 2.0 .7
Mozilla Firefox 2.0 .3
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Mozilla Firefox 1.5.0.3
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 1.5.0.2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 RC2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 1.5.0.1
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 1.5.0.7
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla SeaMonkey 1.1 beta
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla Firefox 1.5.0.6
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0.0.2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla SeaMonkey 1.0 dev
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla Firefox 1.5.0.4
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Slackware Linux 11.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack11.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ seamonkey-1.1.5-i486-1_slack11.0.tgz
Slackware Linux 12.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack12.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ seamonkey-1.1.5-i486-1_slack12.tgz
Slackware Linux -current
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ seamonkey-1.1.5-i486-1.tgz
Mozilla SeaMonkey 1.0.1
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.2
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.5
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.6
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.7
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.9
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.0.99
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.1.1
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla Firefox 1.5 12
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 1.5 .8
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 1.5 beta 2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Slackware Linux 10.2
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz
Mozilla Firefox 2.0 .1
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 .5
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 .7
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 .3
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
References
Mozilla Firefox OnKeyDown Event File Upload Vulnerability
References:
References:
- Bug 388784 (CVE-2007-3511) �?? Firefox file input focus stealing vulnerability (Josh Bressers)
- Vendor Homepage (Mozilla Foundation)
- ASA-2007-447 Firefox security update (RHSA-2007-0979) (Avaya)
- Mozilla Foundation Security Advisory 2007-32 (Mozilla)
- RHSA-2007:0979-1 Critical: firefox security update (Red Hat)
- RHSA-2007:0980-2 Critical: seamonkey security update (Red Hat)
- RHSA-2007:0981-2 Moderate: thunderbird security update (Red Hat)
- Solution 201516 : Multiple Security Vulnerabilities in Firefox and Thunderbir (Sun)
- Sun Alert ID: 103177 (Sun Microsystems)