Mozilla window.sidebar.addSearchEngine() JavaScript exception path disclosure
| mozilla-javascript-path-disclosure (26667) |
Description:
Mozilla Firefox, Mozilla Suite, and Netscape could allow a remote attacker to obtain sensitive information. An attacker could create a malicious Web page that makes a call to the window.sidebar.addSearchEngine() JavaScript function using invalid arguments, which would cause a JavaScript exception to occur that would disclose the full installation path or full path to the victim's user profile.
Platforms Affected:
- MandrakeSoft, Mandrake Linux 2006 X86_64
- MandrakeSoft, Mandrake Linux 2006
- MandrakeSoft, Mandrake Linux Corporate Server 3.0
- MandrakeSoft, Mandrake Linux Corporate Server 3.0 X86_64
- Mozilla, Firefox 1.5.0.1
- Mozilla, Firefox 1.5.0.2
- Mozilla, Firefox 1.5.0.3
- Mozilla, Mozilla Suite 1.7.13
- Netscape, Navigator 7.2
- Netscape, Navigator 8.1
Remedy:
Refer to the Mozilla Web site for patch, upgrade, or suggested workaround information. See References.
Consequences:
Obtain Information
References:
- BugTraq Mailing List, Sun May 21 2006 - 08:20:48 CDT , Firefox 1.5.0.3 Flaw - Page can obtain path to Mozilla installation or profile by examining JavaScript exceptions at http://archives.neohapsis.com/archives/bugtraq/2006-05/0415.html.
- Mozilla Bugzilla Bug 267645, Page can obtain path to Mozilla installation or possibly profile by examining JavaScript exceptions at https://bugzilla.mozilla.org/show_bug.cgi?id=267645.
- BID-18083: Multiple Browsers Exception Handling Information Disclosure Vulnerability
- CVE-2006-2613: Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message contents.
- MDKSA-2006:143: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:143-1: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:145: Updated Firefox packages fix multiple vulnerabilities
- SA20244: Firefox Exception Handling Full Path Disclosure Weakness
- SA20255: Netscape Exception Handling Full Path Disclosure Weakness
- SA20256: Mozilla Suite Exception Handling Full Path Disclosure Weakness
Reported:
May 21, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2009 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
