Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
BID:37120
Info
Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
| Bugtraq ID: | 37120 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4102 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2009 12:00AM |
| Updated: | Dec 15 2009 03:33PM |
| Credit: | Roberto Suggi Liverani and Nick Freeman |
| Vulnerable: |
Peter Andrews Sage 1.4.3 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
The Sage extension for Mozilla Firefox is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Sage 1.4.3 is vulnerable; other versions may also be affected.
The Sage extension for Mozilla Firefox is prone to a cross-domain scripting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Sage 1.4.3 is vulnerable; other versions may also be affected.
Exploit / POC
Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
An attacker must entice a user to subscribe to a malicious feed with the affected extension.
An attacker must entice a user to subscribe to a malicious feed with the affected extension.
Solution / Fix
Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 armel
Debian Linux 5.0 armel
Debian Linux 4.0 m68k
Debian Linux 5.0
Debian Linux 4.0
Debian Linux 4.0 mipsel
Debian Linux 5.0 amd64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 ia-32
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 arm
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0 hppa
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 ia-64
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 4.0 hppa
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 sparc
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 s/390
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0 m68k
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 arm
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 4.0 powerpc
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 alpha
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 armel
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0 armel
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 4.0 m68k
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 4.0
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 mipsel
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0 amd64
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 alpha
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 ia-32
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 mips
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 s/390
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 mipsel
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 5.0 powerpc
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
Debian Linux 4.0 ia-64
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 4.0 mips
-
Debian firefox-sage_1.3.6-4etch1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.3.6-4etch1_all.deb
Debian Linux 5.0 sparc
-
Debian firefox-sage_1.4.2-0.1+lenny1_all.deb
http://security.debian.org/pool/updates/main/f/firefox-sage/firefox-sa ge_1.4.2-0.1+lenny1_all.deb
References
Mozilla Firefox Sage Extension RSS Feeds Cross Domain Scripting Vulnerability
References:
References:
- Extension vulnerability debacle (Sage) (colfer)
- Sage Homepage (Peter Andrews)
- Zero-day vulnerabilities in Firefox extensions discovered (Help Net Security)