Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
BID:28448
Info
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
| Bugtraq ID: | 28448 |
| Class: | Unknown |
| CVE: |
CVE-2007-4879 CVE-2008-1233 CVE-2008-1234 CVE-2008-1235 CVE-2008-1236 CVE-2008-1237 CVE-2008-1238 CVE-2008-1240 CVE-2008-1241 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2008 12:00AM |
| Updated: | Apr 13 2015 09:52PM |
| Credit: | Chris Thomas, Gregory Fleischer, Peter Brodersen, Alexander Klink, moz_bug_r_a4, Boris Zbarsky, Johnny Stenback, Mozilla developers |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_89 Slackware Linux 10.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 rPath rPath Linux 1 Redhat Linux Advanced Workstation 2.1 for the Ita 2.1 IA64 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Mozilla Thunderbird 2.0 .9 Mozilla Thunderbird 2.0 .8 Mozilla Thunderbird 2.0 .6 Mozilla Thunderbird 2.0 .5 Mozilla Thunderbird 2.0 .4 Mozilla Thunderbird 2.0 .12 Mozilla SeaMonkey 1.1.8 Mozilla SeaMonkey 1.1.7 Mozilla SeaMonkey 1.1.6 Mozilla SeaMonkey 1.1.5 Mozilla SeaMonkey 1.1.4 Mozilla SeaMonkey 1.1.3 Mozilla SeaMonkey 1.1.2 Mozilla SeaMonkey 1.1.1 Mozilla Firefox 2.0 .9 Mozilla Firefox 2.0 .8 Mozilla Firefox 2.0 .7 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .10 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0.0.12 Mozilla Firefox 2.0.0.11 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Xulrunner 0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Debian Iceweasel 0 Debian Icedove 0 Debian Iceape 1.1.1 Debian Iceape 1.0.11 Debian Iceape 1.0.10 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 |
| Not Vulnerable: |
Mozilla Thunderbird 2.0 .14 Mozilla SeaMonkey 1.1.9 Mozilla Firefox 2.0.0.13 |
Discussion
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.12 and prior versions.
Exploiting these issues can allow attackers to:
- steal authentication credentials
- obtain potentially sensitive information
- violate the same-origin policy
- execute scripts with elevated privileges
- cause denial-of-service conditions
- potentially execute arbitrary code
- perform cross-site request-forgery attacks
Other attacks are possible.
These issues are present in Firefox 2.0.0.12 and prior versions. Many of these issues are present in Mozilla Thunderbird 2.0.0.12 and prior versions as well as SeaMonkey 1.1.8 and prior versions.
UPDATE: Versions of Mozilla Thunderbird prior to 2.0.0.14 are affected by issues described in MFSA 2008-14 and MFSA 2008-15.
The Mozilla Foundation has released multiple security advisories specifying various vulnerabilities in Firefox 2.0.0.12 and prior versions.
Exploiting these issues can allow attackers to:
- steal authentication credentials
- obtain potentially sensitive information
- violate the same-origin policy
- execute scripts with elevated privileges
- cause denial-of-service conditions
- potentially execute arbitrary code
- perform cross-site request-forgery attacks
Other attacks are possible.
These issues are present in Firefox 2.0.0.12 and prior versions. Many of these issues are present in Mozilla Thunderbird 2.0.0.12 and prior versions as well as SeaMonkey 1.1.8 and prior versions.
UPDATE: Versions of Mozilla Thunderbird prior to 2.0.0.14 are affected by issues described in MFSA 2008-14 and MFSA 2008-15.
Exploit / POC
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
Some of the vulnerabilities described in this BID may not require exploits.
Some of the vulnerabilities described in this BID may not require exploits.
Solution / Fix
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
Solution:
The vendor has released advisories and updates. Please see the references for more information.
Mozilla Firefox 2.0 RC2
Mozilla Firefox 2.0.0.12
Mozilla Firefox 2.0.0.2
Mozilla Firefox 2.0 beta 1
Mozilla Firefox 2.0 .1
Mozilla Firefox 2.0 .9
Mozilla Thunderbird 2.0 .8
Mozilla Thunderbird 2.0 .12
Mozilla Firefox 2.0 .5
Mozilla Thunderbird 2.0 .5
Mozilla Firefox 2.0 .7
Mozilla Firefox 2.0 .10
Mozilla Firefox 2.0 .3
Mozilla Thunderbird 2.0 .4
Mozilla Firefox 2.0 .6
Mozilla Thunderbird 2.0 .6
Mozilla Thunderbird 2.0 .9
Solution:
The vendor has released advisories and updates. Please see the references for more information.
Mozilla Firefox 2.0 RC2
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0.0.12
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0.0.2
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 beta 1
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 .1
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 .9
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Thunderbird 2.0 .8
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .12
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Firefox 2.0 .5
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Thunderbird 2.0 .5
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Firefox 2.0 .7
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 .10
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 .3
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Thunderbird 2.0 .4
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Firefox 2.0 .6
-
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Thunderbird 2.0 .6
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
Mozilla Thunderbird 2.0 .9
-
Mozilla Mozilla Thunderbird Download
http://www.mozilla.com/en-US/thunderbird/all.html
References
Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
References:
References:
- Fixed in Thunderbird 2.0.0.14 (Mozilla Foundation)
- Thunderbird 2.0.0.14 Release Notes (Mozilla Foundation)
- What's New in Firefox 2.0.0.13 (Mozilla Foundation)
- ASA-2008-142 (Avaya)
- ASA-2008-143 (Avaya)
- MFSA 2008-14: JavaScript privilege escalation and arbitrary code execution (Mozilla Foundation)
- MFSA 2008-15: Crashes with evidence of memory corruption (rv:1.8.1.13) (Mozilla Foundation)
- MFSA 2008-16: HTTP Referrer spoofing with malformed URLs (Mozilla Foundation)
- MFSA 2008-17: Privacy issue with SSL Client Authentication (Mozilla Foundation)
- MFSA 2008-18: Java socket connection to any local port via LiveConnect (Mozilla Foundation)
- MFSA 2008-19: XUL popup spoofing variant (cross-tab popups) (Mozilla Foundation)
- RHSA-2008:0207-6 Critical: firefox security update (Red Hat)
- RHSA-2008:0208-16 Critical: seamonkey security update (Red Hat)
- RHSA-2008:0209-3 thunderbird security update (Red Hat)
- Solution 238492 : Multiple Security Vulnerabilities in Solaris 10 Firefox may (Sun)
- Solution 239546: Security Vulnerabilities in Thunderbird for Solaris May Result (Sun Microsystems)