Mozilla window.sidebar.addSearchEngine() JavaScript exception path disclosure
| mozilla-javascript-path-disclosure (26667) |
Description:
Mozilla Firefox, Mozilla Suite, and Netscape could allow a remote attacker to obtain sensitive information. An attacker could create a malicious Web page that makes a call to the window.sidebar.addSearchEngine() JavaScript function using invalid arguments, which would cause a JavaScript exception to occur that would disclose the full installation path or full path to the victim's user profile.
Consequences:
Obtain Information
Remedy:
Refer to the Mozilla Web site for patch, upgrade, or suggested workaround information. See References.
References:
- BugTraq Mailing List, Sun May 21 2006 - 08:20:48 CDT : Firefox 1.5.0.3 Flaw - Page can obtain path to Mozilla installation or profile by examining JavaScript exceptions.
- Mozilla Bugzilla Bug 267645: Page can obtain path to Mozilla installation or possibly profile by examining JavaScript exceptions.
- BID-18083: Multiple Browsers Exception Handling Information Disclosure Vulnerability
- CVE-2006-2613: Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message contents.
- MDKSA-2006:143: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:143-1: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:145: Updated Firefox packages fix multiple vulnerabilities
- SA20244: Firefox Exception Handling Full Path Disclosure Weakness
- SA20255: Netscape Exception Handling Full Path Disclosure Weakness
- SA20256: Mozilla Suite Exception Handling Full Path Disclosure Weakness
Platforms Affected:
- MandrakeSoft Mandrake Linux 2006
- MandrakeSoft Mandrake Linux 2006 X86_64
- MandrakeSoft Mandrake Linux Corporate Server 3.0 X86_64
- MandrakeSoft Mandrake Linux Corporate Server 3.0
- Mozilla Firefox 1.5.0.1
- Mozilla Firefox 1.5.0.2
- Mozilla Firefox 1.5.0.3
- Mozilla Mozilla Suite 1.7.13
- Netscape Navigator 7.2
- Netscape Navigator 8.1
Reported:
May 21, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
