Mozilla Firefox "View Image" security bypass
| firefox-viewimage-security-bypass (25925) |
Description:
Mozilla Firefox could allow a remote attacker to bypass security zone restrictions and obtain sensitive information. An attacker could exploit this vulnerability by creating a malicious Web page containing a specially-crafted image file reference. If a victim could be persuaded to visit the malicious page and then right-click on the image and choose 'View Image', the attacker could access files and resources on the victim's system.
Note: It has been reported that this vulnerability also affects Netscape version 8.1 and Mozilla Suite.
Platforms Affected:
- Debian, Debian Linux 3.1
- Mozilla, Firefox 1.5.0.2
- Netscape, Navigator 7.2
- Netscape, Navigator 8.0.4
- Netscape, Navigator 8.1
- SuSE, SuSE Linux 10.1
- SuSE, SuSE SLES 9
Remedy:
For Mozilla Firefox:
Upgrade to the latest version of Firefox (1.5.0.4 or later), as listed in Mozilla Foundation Security Advisory 2006-39. See References.
For Debian GNU/Linux (Firefox):
Refer to DSA-1120-1 for patch, upgrade, or suggested workaround information. See References.
For Debian GNU/Linux (Mozilla):
Refer to DSA-1118-1 for patch, upgrade, or suggested workaround information. See References.
For Debian GNU/Linux (Thunderbird):
Refer to DSA-1134-1 for patch, upgrade, or suggested workaround information. See References.
For SUSE Linux:
Refer to SUSE-SA:2006:035 for patch, upgrade, or suggested workaround information. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Bypass Security
References:
- BugTraq Mailing List, Tue Apr 18 2006 - 09:38:34 CDT, Another flaw in Firefox 1.5.0.2: to open files from remote at http://archives.neohapsis.com/archives/bugtraq/2006-04/0358.html.
- MFSA 2006-39, "View Image" local resource linking (Windows) at http://www.mozilla.org/security/announce/2006/mfsa2006-39.html.
- Mozilla Bugzilla Bug 334341, Using image tags with a non image file, and selected view image, file will still load up, allowing access to system resources at https://bugzilla.mozilla.org/show_bug.cgi?id=334341.
- ASA-2006-259: HP-UX Firefox Vulnerabilities
- ASA-2007-097: HP-UX Running Firefox Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) (HPSBUX02153)
- BID-18228: Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
- CVE-2006-1942: Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an alternate web page.
- DSA-1118: mozilla -- several vulnerabilities
- DSA-1120: mozilla-firefox -- several vulnerabilities
- DSA-1134: mozilla-thunderbird -- several vulnerabilities
- SA19698: Firefox "View Image" Local Resource Linking Weakness
- SA19988: Netscape "View Image" Local Resource Linking Weakness
- SA20063: Mozilla Suite "View Image" Local Resource Linking Weakness
- SA20376: Firefox Multiple Vulnerabilities
- SECTRACK ID: 1016202: Mozilla Firefox Bugs Permit Arbitrary Code Execution, Cross-Site Scripting, and HTTP Response Smuggling
- SUSE-SA:2006:035: Mozilla browser security problems
- VUPEN/ADV-2006-2106: Mozilla Products Remote Code Execution and Cross Site Scripting Vulnerabilities
- VUPEN/ADV-2006-3748: HP-UX Security Update Fixes Mozilla Firefox Command Execution Vulnerabilities
- VUPEN/ADV-2008-0083: HP-UX Security Update Fixes Firefox Command Execution Vulnerabilities
Reported:
Apr 15, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
