Nessus Plugin #17620
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[GLSA-200503-31] Mozilla Firefox: Multiple vulnerabilities
- Family:
- Gentoo Local Security Checks
- Category:
- infos
- Copyright:
- (C) 2005 Michel Arboi
- Summary:
- Mozilla Firefox: Multiple vulnerabilities
- Version:
- $Revision: 1.1 $
- Cve_id:
- CAN-2005-0399, CAN-2005-0401, CAN-2005-0402
- Bugtraq_id:
- -
- Xrefs:
- GLSA:200503-31
- Description:
- The remote host is affected by the vulnerability described in GLSA-200503-31
(Mozilla Firefox: Multiple vulnerabilities)
The following vulnerabilities were found and fixed in Mozilla
Firefox:
Mark Dowd from ISS X-Force reported an
exploitable heap overrun in the GIF processing of obsolete Netscape
extension 2 (CAN-2005-0399)
Kohei Yoshino discovered that a
page bookmarked as a sidebar could bypass privileges control
(CAN-2005-0402)
Michael Krax reported a new way to bypass XUL
security restrictions through drag-and-drop of items like scrollbars
(CAN-2005-0401)
Impact
The GIF heap overflow could be triggered by a malicious GIF
image that would end up executing arbitrary code with the rights of the
user running Firefox
By tricking the user into bookmarking a
malicious page as a Sidebar, a remote attacker could potentially
execute arbitrary code with the rights of the user running the
browser
By setting up a malicious website and convincing users
to obey very specific drag-and-drop instructions, attackers may
leverage drag-and-drop features to bypass XUL security restrictions,
which could be used as a stepping stone to exploit other
vulnerabilities
Workaround
There is no known workaround at this time.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0399
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0401
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0402
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Solution:
All Mozilla Firefox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.2"
All Mozilla Firefox binary users should upgrade to the latest
version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-bin-1.0.2"
Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.