Secunia CSI 5.0
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA41244

Mozilla Firefox Multiple Vulnerabilities
Secunia Advisory SA41244
DOWNLOAD CSI


DOWNLOAD PSI
Release Date 2010-08-31
Last Update 2010-10-20
   
Popularity 19,023 views
Comments 7 comments

Criticality level Highly criticalHighly critical
Impact Security Bypass
Cross Site Scripting
Spoofing
Privilege escalation
System access
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Software:
Mozilla Firefox 3.5.x
Mozilla Firefox 3.6.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2010-3170 CVSS available in Customer Area
CVE-2010-3173 CVSS available in Customer Area
CVE-2010-3174 CVSS available in Customer Area
CVE-2010-3175 CVSS available in Customer Area
CVE-2010-3176 CVSS available in Customer Area
CVE-2010-3177 CVSS available in Customer Area
CVE-2010-3178 CVSS available in Customer Area
CVE-2010-3179 CVSS available in Customer Area
CVE-2010-3180 CVSS available in Customer Area
CVE-2010-3181 CVSS available in Customer Area
CVE-2010-3182 CVSS available in Customer Area
CVE-2010-3183 CVSS available in Customer Area
  

Description

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct spoofing attacks, bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a user's system.

1) Some unspecified errors in the browser engine can be exploited to corrupt memory and potentially execute arbitrary code.

2) An error when handling very long strings passed to "document.write" can be exploited to overwrite sections of the stack memory and potentially execute arbitrary code.

3) The "locationbar" property of a "window" object is accessible after it has been closed, which can be exploited to e.g. execute arbitrary code.

4) A missing sanity check within the "LookupGetterorSetter()" function when creating or deleting a JavaScript object can result in a dangling pointer being passed to the "JS_ValueToId()" function, which can be exploited to execute arbitrary code by e.g. calling "window.__lookupGetter__" with no arguments.

5) An error within the Gopher parser when generating HTML tags from text can be exploited to conduct cross-site scripting attacks.

6) An error when handling modal calls via "javascript:" URLs can be exploited to bypass the same-origin policy and e.g. gain access to potentially sensitive information from another website.

7) A vulnerability is caused due to the use of vulnerable Network Security Services (NSS) code.

For more information:
SA41237

8) A function uses relative paths to load libraries, which can be exploited to execute arbitrary code by e.g. tricking a user into running the application in a directory containing a malicious library.

Note: This only affects the Windows version.

9) A security issue is caused due to the launch script insecurely setting the environment variable LD_LIBRARY_PATH. This can be exploited to execute arbitrary code e.g. by tricking a user into running the script in a directory containing a malicious library.

Note: This only affects the Linux version.

10) The SSL implementation permits the use of Diffie-Hellman Ephemeral (DHE) with insufficiently secure keys.


Solution
Update to version 3.5.14 or 3.6.11.

Provided and/or discovered by
4) regenrecht, via ZDI
7) Richard Moore and Simon Ward, Westpoint Limited

The vendor credits:
1) Paul Nickerson, Jesse Ruderman, Olli Pettay, Igor Bukanov, Josh Soref, Gary Kwong, Martijn Wargers, and Siddharth Agarwal
2) Alexander Miller
3) Sergey Glazunov
5) Robert Swiecki, Google
6) Eduardo Vela Nava
8) Ehsan Akhgari, Mozilla
9) Dmitri Gribenko
10) Nelson Bolyard, Mozilla

Changelog
Further details available in Customer Area

Original Advisory
Mozilla:
http://www.mozilla.org/security/announce/2010/mfsa2010-64.html
http://www.mozilla.org/security/announce/2010/mfsa2010-65.html
http://www.mozilla.org/security/announce/2010/mfsa2010-66.html
http://www.mozilla.org/security/announce/2010/mfsa2010-67.html
http://www.mozilla.org/security/announce/2010/mfsa2010-68.html
http://www.mozilla.org/security/announce/2010/mfsa2010-69.html
http://www.mozilla.org/security/announce/2010/mfsa2010-70.html
http://www.mozilla.org/security/announce/2010/mfsa2010-71.html
http://www.mozilla.org/security/announce/2010/mfsa2010-72.html

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-10-219/

Westpoint Limited:
http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt

Other references
Further details available in Customer Area

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Mozilla Firefox Multiple Vulnerabilities
 
User Message
[+]

mgroves

RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
This reply has been minimised due to a negative Relevancy Score.

rheston

RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
[+]
This reply has been minimised due to a negative Relevancy Score.
Anthony Wells RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
Expert Contributor 26th Sep, 2010 12:20
Score: 2057
Posts: 2,896
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

This vulnerability is not patched by version 3.6.10 which was/is only a stability/bug fix for version 3.6.9 .

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+7
-0

irishfeat

RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
[+]
This reply has been minimised due to a negative Relevancy Score.
palisade RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
Member 4th Oct, 2010 18:57
Score: 36
Posts: 16
User Since: 26th Feb 2010
System Score: N/A
Location: US
Last edited on 4th Oct, 2010 18:57
Confirmed that this was not fixed in 3.6.10, it only contained a blocklist update, and startup crash fix:

https://bugzilla.mozilla.org/buglist.cgi?quicksear...

---snip---

The Mozilla team has a fix for it already completed though:
https://bugzilla.mozilla.org/show_bug.cgi?id=59530...

Wan-Teh Chang 2010-09-10 12:53:15 PDT
mozilla-central is using NSS_3_12_8_BETA2. I'd like to
update to NSS_3_12_8_BETA3. I summarize the changes between
Beta 2 and Beta 3 below for Mozilla drivers.

Bug fixes of interest to Mozilla:
- Bug 578697: (CVE-2010-3170) Browser Wildcard Certificate Validation Issue
...[truncated the remaining bug fixes for readability]...

---snip---

I have confirmed with the developers via Mozilla's IRC server that 3.6.11 will contain a patch to solve this particular vulnerability.

Hope this helps someone.
Was this reply relevant?
+6
-0
flashbacknl RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
Member 20th Oct, 2010 02:38
Score: 2
Posts: 1
User Since: 20th Oct 2010
System Score: N/A
Location: NL
Last edited on 20th Oct, 2010 02:38
firefox 3.6.11 got released advisory can be changed to patched
Was this reply relevant?
+2
-0
DHC-22 RE: Mozilla Firefox NSS Certificate IP Address Wildcard Matching Vulnerability
Member 21st Oct, 2010 18:21
Score: 9
Posts: 20
User Since: 10th Jun 2010
System Score: N/A
Location: US
The Firefox add-on, Verify Redirect: will this help combat the cross-scripting?
And having Java uninstalled? And Flash turned off?

- David
Was this reply relevant?
+0
-1

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability