Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 91859
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Bryan Østergaard (RETIRED) <kloeri@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 91859 depends on: Show dependency tree
Bug 91859 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-05-08 00:12 0000
See:

http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0123.html

http://www.securityfocus.com/archive/1/397747/2005-05-05/2005-05-11/0

------- Comment #1 From Sune Kloppenborg Jeppesen 2005-05-08 00:13:51 0000 -------
Mozilla please advise.

------- Comment #2 From Adir Abraham 2005-05-08 14:37:00 0000 -------
Updates (solution?) from Secunia:

Mozilla Firefox is prone to a security vulnerability that could result in the execution of arbitrary code without requiring user interaction.

Initial analysis of the vulnerability reveals that the vulnerability relies on a three-stage attack that may lead to an arbitrary script gaining 'UniversalXPConnect' privileges.

It was observed that this issue might be exploited remotely to take privileged actions on the vulnerable computer in the context of the user that is running the affected browser.

This vulnerability is reported in all versions of Mozilla Firefox browsers up to 1.0.3.

*Update: The cross-site scripting vulnerability that the publicly available exploit relied on in the mozilla.org domain has been fixed. This issue is no longer exploitable through this public attack vector.

Workaround:
Symantec has tested the following workaround that can be used to prevent exploitation of this issue.

Disable JavaScript:
-In the Firefox 'Tools' Menu, select 'Options'.
-Select the 'Web Features' dialog.
-Uncheck the 'Enable JavaScript' check box.
-Click the OK button.

http://www.securityfocus.com/bid/13544

------- Comment #3 From Adir Abraham 2005-05-08 14:53:16 0000 -------
Sorry, the last one was from securityfocus.
However, secunia has this update:

Description:
Two vulnerabilities have been discovered in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.

1) The problem is that "IFRAME" JavaScript URLs are not properly protected from being executed in context of another URL in the history list. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site.

2) Input passed to the "IconURL" parameter in "InstallTrigger.install()" is not properly verified before being used. This can be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL.

Successful exploitation requires that the site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org").

A combination of vulnerability 1 and 2 can be exploited to execute arbitrary code.

NOTE: Exploit code is publicly available.

The vulnerabilities have been confirmed in version 1.0.3. Other versions may also be affected.

Solution:
Disable JavaScript.

http://secunia.com/advisories/15292/

------- Comment #4 From Jean-François Brunette (RETIRED) 2005-05-09 06:23:55 0000 -------
Mozilla is also vulnerable
http://secunia.com/advisories/15296/

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-05-09 22:41:59 0000 -------
Mozilla please advise.

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-05-10 09:33:26 0000 -------
Should we issue a temp GLSA on this?

------- Comment #7 From Sune Kloppenborg Jeppesen 2005-05-11 06:59:44 0000 -------
Ubuntu released patches:

https://www.ubuntulinux.org/support/documentation/usn/usn-124-1

Mozilla please provide an updated ebuild.

------- Comment #8 From Sune Kloppenborg Jeppesen 2005-05-11 21:34:48 0000 -------
*** Bug 92321 has been marked as a duplicate of this bug. ***

------- Comment #9 From Aarni Honka 2005-05-11 21:41:06 0000 -------
Final 1.0.4 has been released by mozilla.

------- Comment #10 From Jory A. Pratt 2005-05-12 00:08:35 0000 -------
1.0.4 added for www-client/mozilla-firefox bin has not been bumped as of yet.

------- Comment #11 From Jory A. Pratt 2005-05-12 00:10:08 0000 -------
I marked for ~arch only all archs need to be added and push for stable as soon
as possible seeing all other versions are effected still.

------- Comment #12 From Jory A. Pratt 2005-05-12 00:26:46 0000 -------
1.0.4-bin is in the TREE mark stable as soon as possible.

------- Comment #13 From Sune Kloppenborg Jeppesen 2005-05-12 00:31:11 0000 -------
Thx Jory.

Arches please test and mark stable.

------- Comment #14 From Sune Kloppenborg Jeppesen 2005-05-12 00:50:21 0000 -------
Mozilla we still need an ebuild for Mozilla Suite 1.7.8.

------- Comment #15 From Sune Kloppenborg Jeppesen 2005-05-12 01:47:41 0000 -------
Two more issues added:
http://www.mozilla.org/security/announce/mfsa2005-43.html
http://www.mozilla.org/security/announce/mfsa2005-44.html

And the original one:
http://www.mozilla.org/security/announce/mfsa2005-42.html

------- Comment #16 From Adir Abraham 2005-05-12 03:03:47 0000 -------
CANs are available too:

CAN-2005-1476, CAN-2005-1477

------- Comment #17 From Lars Weiler (RETIRED) 2005-05-12 05:19:41 0000 -------
mozilla-firefox-1.0.4 stable on ppc.  Should we stay in this bug for the
Mozilla Suite or will it be another bug?

------- Comment #18 From Seemant Kulleen (RETIRED) 2005-05-12 07:22:58 0000 -------
stabled on amd64

------- Comment #19 From Gustavo Zacarias (RETIRED) 2005-05-12 08:54:11 0000 -------
firefox-1.0.4 sparc stable, waiting for regular moz.

------- Comment #20 From Aron Griffis (RETIRED) 2005-05-12 08:59:50 0000 -------
mozilla-1.7.8 and mozilla-bin-1.7.8 are now in portage

------- Comment #21 From Sune Kloppenborg Jeppesen 2005-05-12 09:19:18 0000 -------
Thx Aron,

amd64 and sparc please mark Mozilla stable.

------- Comment #22 From Jory A. Pratt 2005-05-12 09:49:25 0000 -------
*** Bug 92393 has been marked as a duplicate of this bug. ***

------- Comment #23 From Sune Kloppenborg Jeppesen 2005-05-12 09:55:10 0000 -------
Handling stable marking for firefox on bug #92393 and mozilla-suite on bug
#92394.

------- Comment #24 From Lars Weiler (RETIRED) 2005-05-12 16:05:05 0000 -------
Dependencies done for ppc.  Removing from this bug.

------- Comment #25 From Thierry Carrez (RETIRED) 2005-05-13 01:19:36 0000 -------
Please followup to bug 92393 and bug 92394.

------- Comment #26 From Sune Kloppenborg Jeppesen 2005-05-15 03:28:57 0000 -------
GLSA 200505-11

------- Comment #27 From René Nussbaumer 2005-06-26 07:42:46 0000 -------
Already stable on hppa

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug