Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
BID:37780
Info
Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
| Bugtraq ID: | 37780 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2010 12:00AM |
| Updated: | Jan 13 2010 12:00AM |
| Credit: | Nick Freeman |
| Vulnerable: |
Yoono Yoono Firefox Extension 6.1 |
| Not Vulnerable: |
Yoono Yoono Firefox Extension 6.1.1 |
Discussion
Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
The Yoono extension for Mozilla Firefox is prone to a remote code-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to Yoono 6.1.1 are vulnerable.
The Yoono extension for Mozilla Firefox is prone to a remote code-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to run arbitrary code within the 'chrome:' context or run arbitrary commands with the privileges of the user running the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to Yoono 6.1.1 are vulnerable.
Exploit / POC
Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
An attacker must entice a user to view a malicious webpage with the affected extension.
An attacker must entice a user to view a malicious webpage with the affected extension.
Solution / Fix
Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Mozilla Firefox Yoono Extension 'img' Tag DOM Event Handler Remote Code Injection Vulnerability
References:
References:
- Yoono 6.1.1 Release Notes (Yoono)
- Yoono Homepage (Yoono)
- Yoono Firefox Extension - Privileged Code Injection (Nick Freeman
)