Nessus Plugin #17620

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200503-31] Mozilla Firefox: Multiple vulnerabilities

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2005 Michel Arboi
Summary:
Mozilla Firefox: Multiple vulnerabilities
Version:
$Revision: 1.1 $
Cve_id:
CAN-2005-0399, CAN-2005-0401, CAN-2005-0402
Bugtraq_id:
-
Xrefs:
GLSA:200503-31
Description:
The remote host is affected by the vulnerability described in GLSA-200503-31
(Mozilla Firefox: Multiple vulnerabilities)


The following vulnerabilities were found and fixed in Mozilla
Firefox:
Mark Dowd from ISS X-Force reported an
exploitable heap overrun in the GIF processing of obsolete Netscape
extension 2 (CAN-2005-0399)
Kohei Yoshino discovered that a
page bookmarked as a sidebar could bypass privileges control
(CAN-2005-0402)
Michael Krax reported a new way to bypass XUL
security restrictions through drag-and-drop of items like scrollbars
(CAN-2005-0401)

Impact

The GIF heap overflow could be triggered by a malicious GIF
image that would end up executing arbitrary code with the rights of the
user running Firefox
By tricking the user into bookmarking a
malicious page as a Sidebar, a remote attacker could potentially
execute arbitrary code with the rights of the user running the
browser
By setting up a malicious website and convincing users
to obey very specific drag-and-drop instructions, attackers may
leverage drag-and-drop features to bypass XUL security restrictions,
which could be used as a stepping stone to exploit other
vulnerabilities

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0399
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0401
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0402
http://www.mozilla.org/projects/security/known-vulnerabilities.html


Solution:
All Mozilla Firefox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-1.0.2"
All Mozilla Firefox binary users should upgrade to the latest
version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/mozilla-firefox-bin-1.0.2"


Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.