Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
BID:38288
Info
Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
| Bugtraq ID: | 38288 |
| Class: | Design Error |
| CVE: |
CVE-2010-0162 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Georgi Guninski |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 SuSE SUSE Linux Enterprise Server 11 DEBUGINFO SuSE SUSE Linux Enterprise Server 11 SuSE SUSE Linux Enterprise Server 10 SP3 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP3 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE Suse Linux Enterprise Desktop 11 SuSE Suse Linux Enterprise Desktop 10 SP3 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE Moblin 2.1 SuSE Moblin 2.0 Slackware Linux x86_64 -current Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux -current S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux EUS 5.4.z server Redhat Enterprise Linux ES 4.8.z Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4.8.z Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Pardus Linux 2009 0 Mozilla SeaMonkey 2.0.2 Mozilla SeaMonkey 2.0.1 Mozilla SeaMonkey 2.0 Mozilla Firefox 3.5.7 Mozilla Firefox 3.5.6 Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.17 Mozilla Firefox 3.0.16 Mozilla Firefox 3.0.15 Mozilla Firefox 3.0.14 Mozilla Firefox 3.0.13 Mozilla Firefox 3.0.12 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.0 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX R1.1 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX LX 1.0 |
| Not Vulnerable: |
Mozilla SeaMonkey 2.0.3 Mozilla Firefox 3.5.8 Mozilla Firefox 3.0.18 Mozilla Firefox 3.6 |
Discussion
Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
Mozilla Firefox and SeaMonkey are prone to a cross-domain scripting vulnerability because they fail to properly handle SVG documents referenced via the 'embed' tag.
Attackers may leverage this issue to execute arbitrary script code within the context of targeted sites; this may allow the attacker to steal cookie-based authentication credentials or to launch other attacks.
Mozilla Firefox and SeaMonkey are prone to a cross-domain scripting vulnerability because they fail to properly handle SVG documents referenced via the 'embed' tag.
Attackers may leverage this issue to execute arbitrary script code within the context of targeted sites; this may allow the attacker to steal cookie-based authentication credentials or to launch other attacks.
Exploit / POC
Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
Solution / Fix
Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux -current
Slackware Linux 12.2
S.u.S.E. openSUSE 11.0
Slackware Linux x86_64 -current
S.u.S.E. openSUSE 11.1
Solution:
Updates are available. Please see the references for more information.
Slackware Linux -current
-
Slackware seamonkey-2.0.3-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ seamonkey-2.0.3-i486-1.txz -
Slackware seamonkey-solibs-2.0.3-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/se amonkey-solibs-2.0.3-i486-1.txz
Slackware Linux 12.2
-
Slackware mozilla-firefox-3.0.18-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ mozilla-firefox-3.0.18-i686-1.tgz -
Slackware seamonkey-2.0.3-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ seamonkey-2.0.3-i486-1_slack12.2.tgz
S.u.S.E. openSUSE 11.0
-
SuSE mozilla-xulrunner190-1.9.0.18-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/mozilla-xulrunner190 -1.9.0.18-0.1.i586.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.i586.rpm
http://download.opensuse.org/update/11.0/rpm/i586/mozilla-xulrunner190 -translations-1.9.0.18-0.1.i586.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.ppc.rpm
http://download.opensuse.org/update/11.0/rpm/ppc/mozilla-xulrunner190- translations-1.9.0.18-0.1.ppc.rpm -
SuSE MozillaFirefox-translations-3.0.18-0.1.ppc.rpm
http://download.opensuse.org/update/11.0/rpm/ppc/MozillaFirefox-transl ations-3.0.18-0.1.ppc.rpm
Slackware Linux x86_64 -current
-
Slackware seamonkey-2.0.3-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ xap/seamonkey-2.0.3-x86_64-1.txz -
Slackware seamonkey-solibs-2.0.3-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/seamonkey-solibs-2.0.3-x86_64-1.txz
S.u.S.E. openSUSE 11.1
-
SuSE mozilla-xulrunner190-debugsource-1.9.0.18-0.1.1.i586.rpm
http://download.opensuse.org/debug/update/11.1/rpm/i586/mozilla-xulrun ner190-debugsource-1.9.0.18-0.1.1.i586.rpm -
SuSE mozilla-xulrunner190-debugsource-1.9.0.18-0.1.1.ppc.rpm
http://download.opensuse.org/debug/update/11.1/rpm/ppc/mozilla-xulrunn er190-debugsource-1.9.0.18-0.1.1.ppc.rpm -
SuSE mozilla-xulrunner190-translations-1.9.0.18-0.1.1.x86_64.rpm
http://download.opensuse.org/update/11.1/rpm/x86_64/mozilla-xulrunner1 90-translations-1.9.0.18-0.1.1.x86_64.rpm
References
Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- ASA-2010-058 firefox security update (RHSA-2010-0112) (Avaya)
- Mozilla Foundation Security Advisory 2010-05 (Mozilla)
- RHSA-2010:0112 firefox security update (Red Hat)
- Ubuntu Security Notice USN-895-1 (Ubuntu)
- Ubuntu Security Notice USN-896-1 (Ubuntu)