Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
BID:31611
Info
Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
| Bugtraq ID: | 31611 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4582 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2008 12:00AM |
| Updated: | May 15 2009 11:56PM |
| Credit: | Liu Die Yu |
| Vulnerable: |
Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self-Service - CCSS7 0 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
Mozilla Firefox is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy when handling internet shortcut files.
An attacker may create a malicious webpage that can access the properties of another domain. This may allow the attacker to obtain sensitive information or launch other attacks against a user of the browser.
Firefox 3.0.1 through 3.0.3 for Microsoft Windows are vulnerable; other versions may also be affected.
Mozilla Firefox is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy when handling internet shortcut files.
An attacker may create a malicious webpage that can access the properties of another domain. This may allow the attacker to obtain sensitive information or launch other attacks against a user of the browser.
Firefox 3.0.1 through 3.0.3 for Microsoft Windows are vulnerable; other versions may also be affected.
Exploit / POC
Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
An example exploit is available. The following internet shortcut files are also required:
'testurl1.url':
[InternetShortcut]
URL=about:cache?device=memory
IDList=
[{000214A0-0000-0000-C000-000000000046}]
Prop3=19,2
'testurl2.url':
[InternetShortcut]
URL=about:cache?device=disk
IDList=
[{000214A0-0000-0000-C000-000000000046}]
Prop3=19,2
An example exploit is available. The following internet shortcut files are also required:
'testurl1.url':
[InternetShortcut]
URL=about:cache?device=memory
IDList=
[{000214A0-0000-0000-C000-000000000046}]
Prop3=19,2
'testurl2.url':
[InternetShortcut]
URL=about:cache?device=disk
IDList=
[{000214A0-0000-0000-C000-000000000046}]
Prop3=19,2
Solution / Fix
Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability
References:
References: