Secunia CSI 5.0
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA43550

Mozilla Firefox / SeaMonkey Multiple Vulnerabilities
Secunia Advisory SA43550
DOWNLOAD CSI


DOWNLOAD PSI
Release Date 2011-03-02
Last Update 2011-03-03
   
Popularity 6,938 views
Comments 1 comment

Criticality level Highly criticalHighly critical
Impact Cross Site Scripting
Spoofing
DoS
System access
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
   
Software:
Mozilla Firefox 3.5.x
Mozilla Firefox 3.6.x
Mozilla SeaMonkey 2.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2010-1585 CVSS available in Customer Area
CVE-2011-0051 CVSS available in Customer Area
CVE-2011-0053 CVSS available in Customer Area
CVE-2011-0054 CVSS available in Customer Area
CVE-2011-0055 CVSS available in Customer Area
CVE-2011-0056 CVSS available in Customer Area
CVE-2011-0057 CVSS available in Customer Area
CVE-2011-0058 CVSS available in Customer Area
CVE-2011-0059 CVSS available in Customer Area
CVE-2011-0061 CVSS available in Customer Area
CVE-2011-0062 CVSS available in Customer Area
  

Description

A weakness and some vulnerabilities have been reported in Mozilla Firefox and SeaMonkey, which can be exploited by malicious people to conduct spoofing attacks, cross-site request forgery attacks, and compromise a user's system.

1) Multiple errors in the browser engine can be exploited to corrupt memory and potentially execute arbitrary code.

2) An error when handling recursive calls to "eval()" within a "try/catch" statement can lead to dialogs being displayed incorrectly and returning "true" when being closed. This can e.g. be exploited to gain escalated privileges by forcing a user into accepting certain dialogs.

3) A use-after-free error in the js3250.dll library when processing the "JSON.stringify()" method can be exploited to dereference an invalid pointer in a call to the "js_HasOwnProperty()" function.

4) An error within the internal memory mapping of non-local JavaScript variables can be exploited to cause a buffer overflow and potentially execute arbitrary code.

5) An error within the internal string mapping of the JavaScript engine related to an offset pointer when handling more than 64K values can be exploited to cause an exception object to be read from invalid memory.

6) A use-after-free error related to JavaScript "Workers" can be exploited to dereference invalid memory and execute arbitrary code.

7) An error when allocating memory for layout objects displaying long strings can be exploited to cause a memory corruption and execute arbitrary code.

Note: This may only affect the Windows platform.

8) The "ParanoidFragmentSink" class does not properly filter "javascript:" URLs and inline JavaScript, which can be exploited to execute arbitrary JavaScript code.

Successful exploitation requires that e.g. an extension using the function to sanitise HTML code before embedding it in a chrome document is installed.

9) An error when decoding certain JPEG images can be exploited to cause a buffer overflow and potentially execute arbitrary code.

Note: This does not affect the Mozilla Firefox 3.5 branch.

10) When a request initiated by the plugin received a redirect response (307), the request including any custom headers is incorrectly forwarded to the new location without notifying the plugin, which can be used to e.g. bypass cross-site request forgery protections relying on custom headers.


Solution
Update to Mozilla Firefox version 3.5.17 or 3.6.14 and Mozilla SeaMonkey version 2.0.12.

Provided and/or discovered by
3) regenrecht, via ZDI
8) Reported by the vendor

The vendor credits:
1) Jesse Ruderman, Igor Bukanov, Olli Pettay, Gary Kwong, Jeff Walden, Henry Sivonen, Martijn Wargers, David Baron, and Marcia Knous
2) Zach Hoffman
4, 5) Christian Holler
6) Daniel Kozlowski
7) Alex Miller
9) Jordi Chancel
10) Peleus Uhley, Adobe

Changelog
Further details available in Customer Area

Original Advisory
1) http://www.mozilla.org/security/announce/2011/mfsa2011-01.html
2) http://www.mozilla.org/security/announce/2011/mfsa2011-02.html
3) http://www.mozilla.org/security/announce/2011/mfsa2011-03.html
4) http://www.mozilla.org/security/announce/2011/mfsa2011-04.html
5) http://www.mozilla.org/security/announce/2011/mfsa2011-05.html
6) http://www.mozilla.org/security/announce/2011/mfsa2011-06.html
7) http://www.mozilla.org/security/announce/2011/mfsa2011-07.html
8) http://www.mozilla.org/security/announce/2011/mfsa2011-08.html
9) http://www.mozilla.org/security/announce/2011/mfsa2011-09.html
10) http://www.mozilla.org/security/announce/2011/mfsa2011-10.html

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-11-103/

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Mozilla Firefox / SeaMonkey Multiple Vulnerabilities
 
User Message
howiem9999 RE: Mozilla Firefox / SeaMonkey Multiple Vulnerabilities
Member 20th Mar, 2011 21:29
Score: 2
Posts: 28
User Since: 8th Dec 2008
System Score: 100%
Location: TH
Last edited on 20th Mar, 2011 21:31
The update for FF 3.6.15 has not been released yet. The links lead to version 3.5.15 which is the current version and has been around for a while.

--
howiem
Was this reply relevant?
+1
-0

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability