Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
BID:26132
Info
Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
| Bugtraq ID: | 26132 |
| Class: | Unknown |
| CVE: |
CVE-2007-5338 CVE-2007-5337 CVE-2007-5334 CVE-2007-5340 CVE-2007-5339 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2007 12:00AM |
| Updated: | Apr 24 2008 10:17PM |
| Credit: | The Mozilla Foundation credits L. David Baron, Boris Zbarsky, Georgi Guninski, Paul Nickerson, Olli Pettay, Jesse Ruderman, Vladimir Sukhoy, Daniel Veditz, Martijn Wargers, Eli Friedman and moz_bug_r_a4 for discovery and reporting of these issues. |
| Vulnerable: |
Warpzilla Enhanced Gecko 1.8.1.7 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10.SP1 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc Sun Solaris 10_x86 Sun Solaris 10 Slackware Linux 10.2 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Fedora Core6 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 Mozilla Thunderbird 2.0 .6 Mozilla Thunderbird 2.0 .5 Mozilla Thunderbird 2.0 .4 Mozilla SeaMonkey 1.1.4 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla SeaMonkey 1.1 beta Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.3 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Camino 1.5.1 Mozilla Camino 1.0.3 Mozilla Camino 1.0.2 Mozilla Camino 1.0.1 Mozilla Camino 1.5 Mozilla Camino 1.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Debian Iceweasel 0 Debian Iceape 1.1.1 Debian Iceape 1.0.11 Debian Iceape 1.0.10 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: |
Warpzilla Enhanced Gecko 1.8.1.8 Mozilla Thunderbird 2.0 .9 Mozilla Thunderbird 1.5.0.14 Mozilla SeaMonkey 1.1.5 Mozilla Firefox 2.0 .8 Mozilla Camino 1.5.2 |
Discussion
Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.7 and prior versions.
These vulnerabilities allow attackers to:
- Execute arbitrary code due to memory corruption.
- Carry out content spoofing and phishing attacks.
- Gain unauthorized access to files on a user's computer running the Linux operating system.
- Execute script code with elevated privileges.
Other attacks may also be possible.
These issues are present in Firefox 2.0.0.7 and prior versions. Mozilla Thunderbird 2.0.0.7 and prior versions as well as SeaMonkey 1.1.4 and prior versions are also affected by many of these vulnerabilities.
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.7 and prior versions.
These vulnerabilities allow attackers to:
- Execute arbitrary code due to memory corruption.
- Carry out content spoofing and phishing attacks.
- Gain unauthorized access to files on a user's computer running the Linux operating system.
- Execute script code with elevated privileges.
Other attacks may also be possible.
These issues are present in Firefox 2.0.0.7 and prior versions. Mozilla Thunderbird 2.0.0.7 and prior versions as well as SeaMonkey 1.1.4 and prior versions are also affected by many of these vulnerabilities.
Exploit / POC
Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
Some of the vulnerabilities described in this BID may not require exploits.
Some of the vulnerabilities described in this BID may not require exploits.
Solution / Fix
Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Mozilla Firefox 2.0 RC2
Sun Solaris 10
Mozilla SeaMonkey 1.1 beta
Mozilla Firefox 2.0.0.2
Mozilla Firefox 2.0.0.3
Slackware Linux 11.0
Slackware Linux 12.0
Slackware Linux -current
Mozilla Firefox 2.0 beta 1
Mozilla Camino 1.0.1
Mozilla Camino 1.0.2
Mozilla SeaMonkey 1.1.1
Mozilla SeaMonkey 1.1.4
Slackware Linux 10.2
Mozilla Firefox 2.0 .1
Mozilla Firefox 2.0 .5
Mozilla Thunderbird 2.0 .5
Mozilla Firefox 2.0 .7
Mozilla Firefox 2.0 .3
Mozilla Thunderbird 2.0 .4
Mozilla Firefox 2.0 .6
Mozilla Thunderbird 2.0 .6
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Mozilla Firefox 2.0 RC2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Sun Solaris 10
-
Sun 125539-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125539-02-1 -
Sun 125541-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -125541-02-1
Mozilla SeaMonkey 1.1 beta
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla Firefox 2.0.0.2
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0.0.3
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Slackware Linux 11.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack11.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ seamonkey-1.1.5-i486-1_slack11.0.tgz
Slackware Linux 12.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack12.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ seamonkey-1.1.5-i486-1_slack12.tgz
Slackware Linux -current
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ seamonkey-1.1.5-i486-1.tgz
Mozilla Firefox 2.0 beta 1
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Camino 1.0.1
-
Cuyahoga Camino-1.5.2.dmg
http://download.mozilla.org/?product=camino-1.5.2&os=osx&lang=en-US
Mozilla Camino 1.0.2
-
Cuyahoga Camino-1.5.2.dmg
http://download.mozilla.org/?product=camino-1.5.2&os=osx&lang=en-US
Mozilla SeaMonkey 1.1.1
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Mozilla SeaMonkey 1.1.4
-
Mozilla SeaMonkey 1.1.5
http://www.mozilla.org/projects/seamonkey/
Slackware Linux 10.2
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz
Mozilla Firefox 2.0 .1
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 .5
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Thunderbird 2.0 .5
-
Mozilla Thunderbird 2.0.0.8
http://www.mozilla.com/en-US/thunderbird/
Mozilla Firefox 2.0 .7
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Firefox 2.0 .3
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Thunderbird 2.0 .4
-
Mozilla Thunderbird 2.0.0.8
http://www.mozilla.com/en-US/thunderbird/
Mozilla Firefox 2.0 .6
-
Mozilla Firefox 2.0.0.8
http://www.mozilla.com/en-US/firefox/
Mozilla Thunderbird 2.0 .6
-
Mozilla Thunderbird 2.0.0.8
http://www.mozilla.com/en-US/thunderbird/
References
Mozilla Firefox 2.0.0.7 Multiple Remote Vulnerabilities
References:
References:
- Bug 381146 (CVE-2007-5337) �?? [FIX]sftp protocol allows file stealing under certa (G30rgi)
- Bug 391043 (CVE-2007-5334) �?? Content can hide the window's titlebar (Eli Friedman)
- Camino 1.5.2 Release Notes (Mozilla)
- Netscape Navigator Release Notes (Netscape)
- Thunderbird 1.5.0.14 Release Notes (Mozilla)
- Warpzilla Enhanced Gecko 1.8.1.8 Release Notes (WarpZilla Enhanced)
- ASA-2007-447 Firefox security update (RHSA-2007-0979) (Avaya)
- HPSBUX02156 SSRT061236 rev.4 - HP-UX Running Thunderbird, Remote Unauthorized Ac (HP)
- Mozilla Foundation Security Advisory 2007-29 (Mozilla)
- Mozilla Foundation Security Advisory 2007-33 (Mozilla)
- Mozilla Foundation Security Advisory 2007-34 (Mozilla)
- Mozilla Foundation Security Advisory 2007-35 (Mozilla)
- RHSA-2007:0979-1 Critical: firefox security update (Red Hat)
- RHSA-2007:0980-2 Critical: seamonkey security update (Red Hat)
- RHSA-2007:0981-2 Moderate: thunderbird security update (Red Hat)
- Solution 201516 : Multiple Security Vulnerabilities in Firefox and Thunderbir (Sun)
- Sun Alert ID: 103177 (Sun Microsystems)