Monday, May 16, 2005

Mozilla Firefox Arbitrary Code Execution

Mozilla Firefox (originally known as Phoenix and briefly as Mozilla Firebird) is "a free, cross-platform, graphical web browser developed by the Mozilla Foundation and hundreds of volunteers".

Two vulnerabilities have been discovered in Firefox, which can be exploited by malicious people to run malicious code on vulnerable systems and compromise its integrity.

Vulnerable Systems:
* Mozilla Firefox version 1.0.3

This proof of concept involve exploiting two flaws:
1) Tricking Firefox into thinking a software installation is being triggered by a whitelisted site, using history stored trusted URL.
2) Software installation trigger not sufficiently checking image URLs containing JavaScript code.

Workaround:
Disable software installation (Web Features panel of the Options/Preferences window in Firefox 1.0.3 or the Content panel in the latest trunk builds).

Vendor Status:
The Mozilla Foundation patched (partially) this issue on the server side by adding random letters and numbers to the install function, which will prevent this exploit from working. We anticipate that the Mozilla Foundation will release a Firefox 1.0.4 update shortly.

Bugzilla:
https://bugzilla.mozilla.org/show_bug.cgi?id=292691 (limited access)

Additional Information:
The information has been provided by tuytumadre@att.net.
The original article can be found at: http://greyhatsecurity.org/vulntests/ffrc.htm

This article taken from: http://www.securiteam.com

0 Comments:

Post a Comment

<< Home