|
 |
|
Mozilla Firefox Multiple Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA23282
|
|
|
Release Date:
|
2006-12-19
|
|
Last Update:
|
2007-01-19
|
|
|
Critical:
|

Highly critical
|
|
Impact:
|
Cross Site Scripting Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Mozilla Firefox 1.x Mozilla Firefox 2.0.x
|
| | CVE reference: | CVE-2006-6497 (Secunia mirror) CVE-2006-6498 (Secunia mirror) CVE-2006-6499 (Secunia mirror) CVE-2006-6500 (Secunia mirror) CVE-2006-6501 (Secunia mirror) CVE-2006-6502 (Secunia mirror) CVE-2006-6503 (Secunia mirror) CVE-2006-6504 (Secunia mirror) CVE-2006-6506 (Secunia mirror) CVE-2006-6507 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Multiple vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to gain knowledge of certain information, conduct cross-site scripting attacks, and potentially compromise a user's system.
1)Various errors in the layout engine and JavaScript engine can be exploited to cause memory corruption and some may potentially allow execution of arbitrary code.
2) An error when reducing the CPU's floating point precision, which may happen on Windows when loading a plugin creating a Direct3D device, may cause the "js_dtoa()" function to not exit and instead cause a memory corruption.
3) A boundary error when setting the cursor to a Windows bitmap using the CSS cursor property can be exploited to cause a heap-based buffer overflow.
4) An unspecified error in the "watch()" JavaScript function can be exploited to execute arbitrary code.
5) An error in LiveConnect causes an already freed object to be used and may potentially allow execution of arbitrary code.
6) An error in the handling of the "src" attribute of IMG elements loaded in a frame can be exploited to change the attribute to a "javascript:" URI. This allows execution of arbitrary HTML and script code in a user's browser session.
7) An error within the handling of SVG comment objects can be exploited to cause a memory corruption and allows execution of arbitrary code by appending an SVG comment object from one document into another type of document (e.g. HTML).
8) The "Feed Preview" feature of Firefox 2.0 may leak feed-browsing habits to websites when retrieving the icons of installed web-based feed viewers.
9) A Function prototype regression in Firefox 2.0 can be exploited to execute arbitrary HTML and script code in a user's browser session.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Solution: Update to version 1.5.0.9 or 2.0.0.1.
Provided and/or discovered by: The vendor credits the following:
1) Andrew Miller, David Baron, moz_bug_r_a4, Georgi Guninski, Jesse Ruderman, Olli Pettay, Igor Bukanov, and Vladimir Vukicevic.
2) Keith Victor
3) Frederik Reiss
4) Shutdown
5) Steven Michaud
6) moz_bug_r_a4
7) An anonymous person via ZDI.
8) Jared Breland
9) moz_bug_r_a4
Changelog: 2006-12-20: Added additional information from ZDI.
2006-12-21: Added link to US-CERT.
2007-01-19: Added links to US-CERT.
Original Advisory: Mozilla:
http://www.mozilla.org/security/announce/2006/mfsa2006-68.html
http://www.mozilla.org/security/announce/2006/mfsa2006-69.html
http://www.mozilla.org/security/announce/2006/mfsa2006-70.html
http://www.mozilla.org/security/announce/2006/mfsa2006-71.html
http://www.mozilla.org/security/announce/2006/mfsa2006-72.html
http://www.mozilla.org/security/announce/2006/mfsa2006-73.html
http://www.mozilla.org/security/announce/2006/mfsa2006-75.html
http://www.mozilla.org/security/announce/2006/mfsa2006-76.html
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-06-051.html
Other References: US-CERT VU#928956:
http://www.kb.cert.org/vuls/id/928956
US-CERT VU#427972:
http://www.kb.cert.org/vuls/id/427972
US-CERT VU#447772:
http://www.kb.cert.org/vuls/id/447772
US-CERT VU#263412:
http://www.kb.cert.org/vuls/id/263412
US-CERT VU#722244:
http://www.kb.cert.org/vuls/id/722244
US-CERT VU#405092:
http://www.kb.cert.org/vuls/id/405092
US-CERT VU#428500:
http://www.kb.cert.org/vuls/id/428500
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
60 Related Secunia Security Advisories, displaying 10
|
|
|
1. Mozilla Firefox 2 URI Launching Vulnerability
|
|
2. Mozilla Firefox Multiple Vulnerabilities
|
|
3. Mozilla Products CSS Objects Handling Code Execution
|
|
4. Mozilla Firefox Javascript Garbage Collector Vulnerability
|
|
5. Mozilla Firefox Multiple Vulnerabilities
|
|
6. Mozilla Firefox Multiple Vulnerabilities
|
|
7. Mozilla Firefox "chrome:" Directory Traversal Security Issue
|
|
8. Firefox Charset Inheritance Cross-Site Scripting Security Issue
|
|
9. Mozilla Firefox Multiple Vulnerabilities
|
|
10. Mozilla Firefox "jar:" Protocol Handling Cross-Site Scripting Security Issue
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|