Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
BID:35928
Info
Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
| Bugtraq ID: | 35928 |
| Class: | Unknown |
| CVE: |
CVE-2009-2665 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2009 12:00AM |
| Updated: | Aug 21 2009 03:48PM |
| Credit: | Wladimir Palant, moz_bug_r_a4 |
| Vulnerable: |
Red Hat Fedora 11 Red Hat Fedora 10 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 |
| Not Vulnerable: |
Mozilla Firefox 3.5.2 |
Discussion
Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
Mozilla Firefox is prone to a privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary JavaScript code with chrome privileges.
The issue affects Firefox 3.5 prior to 3.5.2.
Mozilla Firefox is prone to a privilege-escalation vulnerability.
Attackers can exploit this issue to execute arbitrary JavaScript code with chrome privileges.
The issue affects Firefox 3.5 prior to 3.5.2.
Exploit / POC
Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
Proofs of concept are available from the associated Mozilla bug reports. Please see the references for more information.
Proofs of concept are available from the associated Mozilla bug reports. Please see the references for more information.
Solution / Fix
Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mozilla Firefox Incorrect Security Wrapper JavaScript Chrome Privilege Escalation Vulnerability
References:
References:
- Bug 498897 - Web code gets 'permission denied' error if a content policy is pr (Mozilla)
- Mozilla Homepage (Mozilla Foundation)
- MFSA 2009-46 - Mozilla Foundation Security Advisory 2009-46 (Mozilla)