Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
BID:24946
Info
Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
| Bugtraq ID: | 24946 |
| Class: | Unknown |
| CVE: |
CVE-2007-3738 CVE-2007-3737 CVE-2007-3736 CVE-2007-3735 CVE-2007-3734 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2007 12:00AM |
| Updated: | Apr 24 2008 10:57PM |
| Credit: | The Mozilla Foundation credits shutdown, moz_bug_r_a4, Bernd Mielke, Boris Zbarsky, David Baron, Daniel Veditz, Jesse Ruderman, Lukas Loehrer, Martijn Wargers, Mats Palmgren, Olli Pettay, Paul Nickerson, Vladimir Sukhoy, Asaf Romano, Igor Bukanov, and the |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux wizpy 0 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 Sun Solaris 10_x86 Sun Solaris 10.0_x86 Sun Solaris 10.0 Sun Solaris 10 Slackware Linux 12.0 Slackware Linux 11.0 SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server 10.SP1 S.u.S.E. Linux Enterprise Server 10 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Mozilla XULRunner 1.8.1.3 Mozilla Thunderbird 2.0 .4 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla SeaMonkey 1.1 beta Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Camino 1.0.3 Mozilla Camino 1.0.2 Mozilla Camino 1.0.1 Mozilla Camino 0.8.4 Mozilla Camino 0.8.3 Mozilla Camino 0.8 Mozilla Camino 0.7 .0 Mozilla Camino 1.5 Mozilla Camino 1.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Iceape Internet Suite Iceape Internet Suite 1.0.10 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Xulrunner 0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Debian Iceweasel 0 Debian Iceape 1.1.1 Debian Iceape 1.0.11 Debian Iceape 1.0.10 Avaya Messaging Storage Server MSS 3.0 |
| Not Vulnerable: |
Mozilla XULRunner 1.8.1.6 Mozilla Thunderbird 2.0 .5 Mozilla SeaMonkey 1.1.3 Mozilla Firefox 2.0 .5 Mozilla Camino 1.5.1 |
Discussion
Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
The Mozilla Foundation has released four security advisories specifying multiple vulnerabilities in Firefox 2.0.0.4.
These vulnerabilities allow attackers to:
- Execute arbitrary code
- Execute code with chrome privileges
- Perform cross-site scripting attacks
- Crash Firefox in a myriad of ways, with evidence of memory corruption.
Other attacks may also be possible.
The Mozilla Foundation has released four security advisories specifying multiple vulnerabilities in Firefox 2.0.0.4.
These vulnerabilities allow attackers to:
- Execute arbitrary code
- Execute code with chrome privileges
- Perform cross-site scripting attacks
- Crash Firefox in a myriad of ways, with evidence of memory corruption.
Other attacks may also be possible.
Exploit / POC
Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
Some of the vulnerabilities described in this BID do not require exploits.
Proof-of-concept exploits are available in the Mozilla Bugzilla database, but are not currently available to the general public.
Some of the vulnerabilities described in this BID do not require exploits.
Proof-of-concept exploits are available in the Mozilla Bugzilla database, but are not currently available to the general public.
Solution / Fix
Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
Solution:
Mozilla has released Firefox 2.0.0.5 to address these issues. SeaMonkey 1.1.3 is not affected. Please see the referenced advisories for information on obtaining and applying fixes.
Slackware Linux 12.0
Mozilla Firefox 2.0 RC2
Mozilla Firefox 2.0 beta 1
Mozilla Camino 1.0
Mozilla Camino 1.5
Sun Solaris 10_x86
Mozilla Firefox 2.0.0.2
Mozilla Camino 0.7 .0
Mozilla Camino 0.8
Mozilla Camino 1.0.1
Mozilla Camino 1.0.2
Mozilla Camino 1.0.3
Mozilla Firefox 2.0 .1
Solution:
Mozilla has released Firefox 2.0.0.5 to address these issues. SeaMonkey 1.1.3 is not affected. Please see the referenced advisories for information on obtaining and applying fixes.
Slackware Linux 12.0
-
Slackware mozilla-firefox-2.0.0.5-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.5-i686-1.tgz -
Slackware mozilla-thunderbird-2.0.0.5-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-thunderbird-2.0.0.5-i686-1.tgz
Mozilla Firefox 2.0 RC2
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Firefox 2.0 beta 1
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Camino 1.0
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.5
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Sun Solaris 10_x86
-
Sun 125540-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125540-02-1 -
Sun 125542-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125542-02-1
Mozilla Firefox 2.0.0.2
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
Mozilla Camino 0.7 .0
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 0.8
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.1
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.2
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Camino 1.0.3
-
Mozilla camino-1.5.1
http://download.mozilla.org/?product=camino-1.5.1&os=osx&lang=en-US
Mozilla Firefox 2.0 .1
-
Mozilla Firefox 2.0.0.5
ftp://ftp.mozilla.org/pub/mozilla.org/firefox/releases/2.0.0.5
References
Mozilla Firefox 2.0.0.4 Multiple Remote Vulnerabilities
References:
References:
- 1.5.1 Release Notes (Camino)
- Mozilla Firefox 2.0.0.5 Release Notes (Mozilla Foundation)
- Mozilla Homepage (Mozilla Foundation)
- Mozilla Updates for Multiple Vulnerabilities (US-CERT)
- rPath Security Advisory: 2007-0148-1 (rPath)
- Security update for MozillaFirefox SuSE Linux Maintenance Web (07d098f99c9fe6956 (Novell)
- ASA-2007-360 - Firefox security update (RHSA-2007-0724) (Avaya)
- HPSBUX02153 SSRT061181 rev.5 - HP-UX Running Firefox, Remote Unauthorized Access (HP)
- HPSBUX02156 SSRT061236 rev.4 - HP-UX Running Thunderbird, Remote Unauthorized Ac (HP)
- Mozilla Foundation Security Advisory 2007-18 (Mozilla Foundation)
- Mozilla Foundation Security Advisory 2007-19 (Mozilla Foundation)
- Mozilla Foundation Security Advisory 2007-21 (Mozilla Foundation)
- Mozilla Foundation Security Advisory 2007-25 (Mozilla Foundation)
- RHSA-2007:0722-3 Critical: seamonkey security update (Red Hat)
- RHSA-2007:0723-4 Moderate: thunderbird security update (Red Hat)
- RHSA-2007:0724-4 Critical: firefox security update (Red Hat)
- Solution 201516 : Multiple Security Vulnerabilities in Firefox and Thunderbir (Sun)
- Sun Alert ID: 103177 (Sun Microsystems)