Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
BID:27683
Info
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
| Bugtraq ID: | 27683 |
| Class: | Unknown |
| CVE: |
CVE-2008-0412 CVE-2008-0413 CVE-2008-0414 CVE-2008-0417 CVE-2008-0419 CVE-2008-0592 CVE-2008-0593 CVE-2008-0594 CVE-2008-0415 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | Apr 16 2015 05:42PM |
| Credit: | The Mozilla Foundation credits Boris Zbarsky, Carsten Book, Charles McAuley, David Bloom, Emil Ljungdahl, Gerry Eisenhaur, Gregory Fleisher, hong, Igor Bukanov, Jesse Ruderman, Justin Dolske, Kai Engert, Lars-Olof Moilanen, Martijn Wargers, Martin Straka , |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux wizpy 0 Turbolinux Turbolinux Server 11 x64 Turbolinux Turbolinux Server 11 Turbolinux FUJI 0 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_89 Slackware Linux 10.2 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Netscape Navigator 9.0 1 Netscape Navigator 9.0.0.5 Netscape Navigator 9.0.0.4 Netscape Navigator 9.0.0.3 Netscape Navigator 9.0.0.2 Netscape Navigator 9.0 Mozilla Thunderbird 2.0 .9 Mozilla Thunderbird 2.0 .8 Mozilla Thunderbird 2.0 .6 Mozilla Thunderbird 2.0 .5 Mozilla Thunderbird 2.0 .4 Mozilla SeaMonkey 1.1.7 Mozilla SeaMonkey 1.1.6 Mozilla SeaMonkey 1.1.5 Mozilla SeaMonkey 1.1.4 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Iceape Internet Suite Iceape Internet Suite 1.0.12 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server 3.1 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: |
Netscape Navigator 9.0.0.6 Mozilla Thunderbird 2.0 .12 Mozilla SeaMonkey 1.1.8 Mozilla Firefox 2.0.0.12 |
Discussion
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.11 and prior versions.
Exploiting these issues can allow attackers to:
- remotely execute arbitrary code
- cause denial-of-service conditions
- hide contents of security warnings
- access sensitive information
- escape sandbox and execute scripts with chrome privileges
- inject script code into other sites and violate the same-origin policy
Other attacks are possible.
These issues are present in Firefox 2.0.0.11 and prior versions. Mozilla Thunderbird 2.0.0.9 and prior versions as well as SeaMonkey 1.1.7 and prior versions are also affected by many of these vulnerabilities.
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.11 and prior versions.
Exploiting these issues can allow attackers to:
- remotely execute arbitrary code
- cause denial-of-service conditions
- hide contents of security warnings
- access sensitive information
- escape sandbox and execute scripts with chrome privileges
- inject script code into other sites and violate the same-origin policy
Other attacks are possible.
These issues are present in Firefox 2.0.0.11 and prior versions. Mozilla Thunderbird 2.0.0.9 and prior versions as well as SeaMonkey 1.1.7 and prior versions are also affected by many of these vulnerabilities.
Exploit / POC
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
Some of the vulnerabilities described in this BID may not require exploits.
Some of the vulnerabilities described in this BID may not require exploits.
Solution / Fix
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Netscape Navigator 9.0.0.5
Netscape Navigator 9.0.0.4
Netscape Navigator 9.0
Netscape Navigator 9.0.0.3
Netscape Navigator 9.0.0.2
Mozilla Thunderbird 2.0 .4
Mozilla Thunderbird 2.0 .6
Mozilla Thunderbird 2.0 .9
Mozilla Thunderbird 2.0 .8
Mozilla Thunderbird 2.0 .5
Netscape Navigator 9.0 1
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Netscape Navigator 9.0.0.5
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
Netscape Navigator 9.0.0.4
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
Netscape Navigator 9.0
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
Netscape Navigator 9.0.0.3
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
Netscape Navigator 9.0.0.2
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
Mozilla Thunderbird 2.0 .4
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .6
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .9
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .8
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .5
-
Mozilla thunderbird 2.0.0.12
http://www.mozilla.com/en-US/thunderbird/all.html
Netscape Navigator 9.0 1
-
Netscape Netscape Navigator 9.0.0.6
http://browser.netscape.com/downloads
References
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.11 Multiple Remote Vulnerabilities
References:
References:
- Fixed in Firefox 2.0.0.12 (Mozilla Foundation)
- MFSA 2008-09: Mishandling of locally-saved plain text files (Mozilla Foundation)
- What's New in Netscape Navigator 9.0.0.6 (Netscape)
- ASA-2008-059: firefox security update (RHSA-2008-0103) (Avaya)
- MFSA 2008-01: Crashes with evidence of memory corruption (rv:1.8.1.12) (Mozilla Foundation)
- MFSA 2008-02: Multiple file input focus stealing vulnerabilities (Mozilla Foundation)
- MFSA 2008-03: Privilege escalation, XSS, Remote Code Execution (Mozilla Foundation)
- MFSA 2008-04: Stored password corruption (Mozilla Foundation)
- MFSA 2008-06: Web browsing history and forward navigation stealing (Mozilla Foundation)
- MFSA 2008-08: File action dialog tampering (Mozilla Foundation)
- MFSA 2008-10: URL token stealing via stylesheet redirect (Mozilla Foundation)
- MFSA 2008-11: Web forgery overwrite with div overlay (Mozilla Foundation)
- RHSA-2008:0103-7 Critical: firefox security update (Red Hat)
- RHSA-2008:0104-4 Critical: seamonkey security update (Red Hat)
- RHSA-2008:0105-4 Moderate: thunderbird security update (Red Hat)
- Security update for epiphany (Novell)
- Solution 238492 : Multiple Security Vulnerabilities in Solaris 10 Firefox may (Sun)
- Solution 239546: Security Vulnerabilities in Thunderbird for Solaris May Result (Sun Microsystems)
- Vulnerability Note VU#879056 Mozilla browsers fail to properly handle images (US-CERT)