Mozilla Firefox chrome:// URI JavaScript File Request Information Disclosure Vulnerability
BID:27406
Info
Mozilla Firefox chrome:// URI JavaScript File Request Information Disclosure Vulnerability
| Bugtraq ID: | 27406 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0418 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2008 12:00AM |
| Updated: | Apr 13 2015 09:30PM |
| Credit: | Gerry Eisenhaur discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_89 Slackware Linux 10.2 Slackware Linux 12.0 Slackware Linux 11.0 rPath rPath Linux 1 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mozilla Thunderbird 2.0 .9 Mozilla Thunderbird 2.0 .8 Mozilla Thunderbird 2.0 .6 Mozilla Thunderbird 2.0 .5 Mozilla Thunderbird 2.0 .4 Mozilla SeaMonkey 1.1.7 Mozilla SeaMonkey 1.1.6 Mozilla SeaMonkey 1.1.5 Mozilla SeaMonkey 1.1.4 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla SeaMonkey 1.1 beta Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: |
Mozilla Thunderbird 2.0 .12 Mozilla SeaMonkey 1.1.8 Mozilla Firefox 2.0.0.12 |
Discussion
Mozilla Firefox chrome:// URI JavaScript File Request Information Disclosure Vulnerability
Mozilla Firefox is prone to an information-disclosure vulnerability because it fails to restrict access to local JavaScript, images and stylesheets files.
Attackers can exploit this issue to gain access to potentially sensitive information that could aid in further attacks.
Firefox 2.0.0.11 is vulnerable; other versions may also be affected.
NOTE: For an exploit to succeed, a user must have an addon installed that does not store its contents in a '.jar' file. The attacker would have to target a specific addon that uses "flat" packaging.
Mozilla Firefox is prone to an information-disclosure vulnerability because it fails to restrict access to local JavaScript, images and stylesheets files.
Attackers can exploit this issue to gain access to potentially sensitive information that could aid in further attacks.
Firefox 2.0.0.11 is vulnerable; other versions may also be affected.
NOTE: For an exploit to succeed, a user must have an addon installed that does not store its contents in a '.jar' file. The attacker would have to target a specific addon that uses "flat" packaging.
Exploit / POC
Solution / Fix
Mozilla Firefox chrome:// URI JavaScript File Request Information Disclosure Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Mozilla Thunderbird 2.0 .4
Mozilla Thunderbird 2.0 .6
Mozilla Thunderbird 2.0 .9
Mozilla Thunderbird 2.0 .8
Mozilla Thunderbird 2.0 .5
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Mozilla Thunderbird 2.0 .4
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .6
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .9
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .8
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .5
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
References
Mozilla Firefox chrome:// URI JavaScript File Request Information Disclosure Vulnerability
References:
References:
- Partial list of flat packaged add-ons (Mozilla Foundation)
- Bug 413250 �?? chrome directory traversal (local disk access via flat addons) (Mozilla Foundation)
- Bug 413451 �?? allows to steal data from sessionstore.js (Mozilla Foundation)
- chrome protocol directory traversal (Mozilla)
- Status update for Chrome Protocol Directory Traversal issue (Mozilla Security Blog)
- Vendor Homepage (Mozilla Foundation)
- ASA-2008-059: firefox security update (RHSA-2008-0103) (Avaya)
- Firefox chrome: URL Handling Directory Traversal (hiredhacker.com)
- MFSA 2008-05: Directory traversal via chrome: URI (Mozilla Foundation)
- RHSA-2008:0103-7 Critical: firefox security update (Red Hat)
- RHSA-2008:0104-4 Critical: seamonkey security update (Red Hat)
- RHSA-2008:0105-4 Moderate: thunderbird security update (Red Hat)
- Security update for epiphany (Novell)
- Solution 238492 : Multiple Security Vulnerabilities in Solaris 10 Firefox may (Sun)
- Solution 239546: Security Vulnerabilities in Thunderbird for Solaris May Result (Sun Microsystems)
- Vulnerability Note VU#309608 Mozilla products may allow directory traversal (US-CERT)