Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
BID:33137
Info
Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
| Bugtraq ID: | 33137 |
| Class: | Design Error |
| CVE: |
CVE-2009-0068 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2009 12:00AM |
| Updated: | Feb 03 2009 10:59PM |
| Credit: | Manuel Reimer |
| Vulnerable: |
Xdg-utils Xdg-utils 0 Slackware Linux 12.2 Slackware Linux -current Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.0 Beta 5 Mozilla Firefox 3.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
Mozilla Firefox is prone to a remote code-execution vulnerability because the browser fails to properly validate the 'mime-type' of files before calling the 'xdg-open' utility, as defined in '/etc/mailcap'.
An attacker can exploit this issue to execute arbitrary code within the context of the affected browser.
This issue affects Firefox running on Slackware Linux 12.2. Other versions may also be vulnerable.
UPDATE (January 8, 2009): The exact fault for this issue is currently unclear. This could be a configuration problem in Slackware Linux, a failure to sanitize input in Firefox, or a problem in 'xdg-open'. We will update this BID pending further investigation.
Mozilla Firefox is prone to a remote code-execution vulnerability because the browser fails to properly validate the 'mime-type' of files before calling the 'xdg-open' utility, as defined in '/etc/mailcap'.
An attacker can exploit this issue to execute arbitrary code within the context of the affected browser.
This issue affects Firefox running on Slackware Linux 12.2. Other versions may also be vulnerable.
UPDATE (January 8, 2009): The exact fault for this issue is currently unclear. This could be a configuration problem in Slackware Linux, a failure to sanitize input in Firefox, or a problem in 'xdg-open'. We will update this BID pending further investigation.
Exploit / POC
Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious file using the affected application.
The following website demonstrates this issue.
NOTE: Symantec urges caution when testing exploits from third-party sources.
https://prefbar.mozdev.org/testxdgopen.html
http://prefbar.mozdev.org/testxdgopen.html
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious file using the affected application.
The following website demonstrates this issue.
NOTE: Symantec urges caution when testing exploits from third-party sources.
https://prefbar.mozdev.org/testxdgopen.html
http://prefbar.mozdev.org/testxdgopen.html
Solution / Fix
Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the referenced for more information.
Solution:
Updates are available. Please see the referenced for more information.
References
Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability
References:
References:
- Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploi (Manuel Reimer )
- Using xdg-open in mailcap causes serious hole in Firefox! (Manuel Reimer )
- Vendor Homepage (Mozilla Foundation)
- Xdg-utils Homepage (Xdg-utils)