Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
BID:35660
Info
Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
| Bugtraq ID: | 35660 |
| Class: | Unknown |
| CVE: |
CVE-2009-2477 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2009 12:00AM |
| Updated: | Aug 24 2009 03:52PM |
| Credit: | SBerry aka Simon Berry-Byrne |
| Vulnerable: |
Sun OpenSolaris build snv_121 Sun OpenSolaris build snv_120 Sun OpenSolaris build snv_119 Red Hat Fedora 11 Mozilla XULRunner 1.9.1 Mozilla XULRunner 1.9.1.1 Mozilla XULRunner 1.9 Mozilla Firefox 3.5 |
| Not Vulnerable: |
Sun OpenSolaris build snv_122 Mozilla Firefox 3.5.1 |
Discussion
Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
Mozilla Firefox is prone to a remote code-execution vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The issue affects Firefox 3.5; other versions may also be vulnerable.
NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP3.
UPDATE (July 15, 2009): Remote code execution is also possible in Firefox 3.5 running on Apple Mac OS X.
Mozilla Firefox is prone to a remote code-execution vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions.
The issue affects Firefox 3.5; other versions may also be vulnerable.
NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP3.
UPDATE (July 15, 2009): Remote code execution is also possible in Firefox 3.5 running on Apple Mac OS X.
Exploit / POC
Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
Some reports indicate that this issue is being exploited in the wild.
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/firefox_35.tar.gz
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Some reports indicate that this issue is being exploited in the wild.
The following commercial exploit is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/firefox_35.tar.gz
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
Solution:
Vendor advisories and fixes are available. Please see the references for details.
Solution:
Vendor advisories and fixes are available. Please see the references for details.
References
Mozilla Firefox 3.5 'TraceMonkey' Component Remote Code Execution Vulnerability
References:
References:
- Bug 503286 - browser crash when search suggestions show [@ js_Interpret ] [@ j (Mozilla)
- About:config entries (Mozilla)
- Critical JavaScript vulnerability in Firefox 3.5 (Mozilla)
- Vendor Homepage (Mozilla Foundation)
- 266148 Firefox (Sun)
- Mozilla Foundation Security Advisory 2009-41 (Mozilla)
- Vulnerability Note VU#443060 Mozilla Firefox 3.5 code execution vulnerability (US-CERT)