Mozilla Firefox and Thunderbird content-defined object prototype code execution
| mozilla-contentdefined-code-execution (26848) |
Description:
Mozilla Firefox and Mozilla Thunderbird could allow a remote attacker to execute arbitrary code on a victim's system, caused by a vulnerability regarding the use of incorrect privileges when calling content-defined setters on an object prototype. An attacker could exploit this vulnerability to gain complete control of a victim's system, if the attacker could persuade the victim to visit a malicious Web page or open a malicious HTML email.
Platforms Affected:
- Canonical, Ubuntu 5.04
- Canonical, Ubuntu 5.10
- Canonical, Ubuntu 6.06 LTS
- Debian, Debian Linux 3.1
- Gentoo, Linux
- MandrakeSoft, Mandrake Linux 2006 X86_64
- MandrakeSoft, Mandrake Linux 2006
- MandrakeSoft, Mandrake Linux Corporate Server 3.0 X86_64
- MandrakeSoft, Mandrake Linux Corporate Server 3.0
- Mozilla, Firefox 0.10
- Mozilla, Firefox 0.10.1
- Mozilla, Firefox 0.8
- Mozilla, Firefox 0.9 rc
- Mozilla, Firefox 0.9
- Mozilla, Firefox 0.9.1
- Mozilla, Firefox 0.9.2
- Mozilla, Firefox 0.9.3
- Mozilla, Firefox 1.0
- Mozilla, Firefox 1.0.1
- Mozilla, Firefox 1.0.2
- Mozilla, Firefox 1.0.3
- Mozilla, Firefox 1.0.4
- Mozilla, Firefox 1.0.5
- Mozilla, Firefox 1.0.6
- Mozilla, Firefox 1.0.7
- Mozilla, Firefox 1.5
- Mozilla, Firefox 1.5 Beta2
- Mozilla, Firefox 1.5 Beta1
- Mozilla, Firefox 1.5.0.1
- Mozilla, Firefox 1.5.0.2
- Mozilla, Firefox 1.5.0.3
- Mozilla, Thunderbird 0.1
- Mozilla, Thunderbird 0.2
- Mozilla, Thunderbird 0.3
- Mozilla, Thunderbird 0.4
- Mozilla, Thunderbird 0.5
- Mozilla, Thunderbird 0.6
- Mozilla, Thunderbird 0.7
- Mozilla, Thunderbird 0.7.1
- Mozilla, Thunderbird 0.7.2
- Mozilla, Thunderbird 0.7.3
- Mozilla, Thunderbird 0.8
- Mozilla, Thunderbird 0.9
- Mozilla, Thunderbird 1.0
- Mozilla, Thunderbird 1.0.1
- Mozilla, Thunderbird 1.0.2
- Mozilla, Thunderbird 1.0.3
- Mozilla, Thunderbird 1.0.4
- Mozilla, Thunderbird 1.0.5
- Mozilla, Thunderbird 1.0.5 Beta
- Mozilla, Thunderbird 1.0.6
- Mozilla, Thunderbird 1.0.7
- Mozilla, Thunderbird 1.5
- Mozilla, Thunderbird 1.5 Beta2
- Mozilla, Thunderbird 1.5.0.1
- RedHat, Enterprise Linux 2.1 ES
- RedHat, Enterprise Linux 2.1 AS
- RedHat, Enterprise Linux 2.1 WS
- RedHat, Enterprise Linux 3 ES
- RedHat, Enterprise Linux 3 WS
- RedHat, Enterprise Linux 3 AS
- RedHat, Enterprise Linux 3 Desktop
- RedHat, Enterprise Linux 4 AS
- RedHat, Enterprise Linux 4 Desktop
- RedHat, Enterprise Linux 4 ES
- RedHat, Enterprise Linux 4 WS
- RedHat, Linux Advanced Workstation 2.1 Itanium
- Sun, Solaris 10
- Sun, Solaris 8
- Sun, Solaris 9
- SuSE, SuSE Linux 10.1
- SuSE, SuSE SLES 9
Remedy:
Refer to Mozilla Foundation Security Advisory 2006-37 for upgrade or suggested workaround information. See References.
For SUSE Linux:
Refer to SUSE-SA:2006:035 for patch, upgrade, or suggested workaround information. See References.
Refer to Sun Alert ID: 102800 for patch, upgrade, or suggested workaround information. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Gain Access
References:
- MFSA 2006-37, Remote compromise via content-defined setter on object prototypes at http://www.mozilla.org/security/announce/2006/mfsa2006-37.html.
- Sun Alert ID: 102800, Security Vulnerabilities in Mozilla 1.7 for Solaris 8, 9 and 10 at http://sunsolve.sun.com/search/document.do?assetkey=1-26-102800-1.
- ASA-2006-146: seamonkey security update (was mozilla) (RHSA-2006-0578)
- ASA-2006-151: firefox seamonkey and thunderbird security update (RHSA-2006-0609 RHSA-2006-0610 and RHSA-2006-0611)
- ASA-2006-208: seamonkey security update (was mozilla) (RHSA-2006-0594)
- ASA-2006-259: HP-UX Firefox Vulnerabilities
- ASA-2007-072: Security Vulnerabilities in Mozilla 1.7 for Solaris 8 9 and 10 (Sun 102800)
- ASA-2007-097: HP-UX Running Firefox Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) (HPSBUX02153)
- ASA-2007-135: HP-UX Running Thunderbird Remote Unauthorized Access or Elevation of Privileges or Denial of Service (HPSBUX02156)
- BID-18228: Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities
- CVE-2006-2776: Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.
- DSA-1118: mozilla -- several vulnerabilities
- DSA-1120: mozilla-firefox -- several vulnerabilities
- DSA-1134: mozilla-thunderbird -- several vulnerabilities
- FrSIRT/ADV-2006-2106: Mozilla Products Remote Code Execution and Cross Site Scripting Vulnerabilities
- FrSIRT/ADV-2006-3748: HP-UX Security Update Fixes Mozilla Firefox Command Execution Vulnerabilities
- FrSIRT/ADV-2006-3749: HP-UX Security Update Fixes Mozilla Thunderbird Code Execution Vulnerabilities
- FrSIRT/ADV-2007-0573: Sun Solaris Mozilla Browser Multiple Remote Command Execution Vulnerabilities
- FrSIRT/ADV-2008-0083: HP-UX Security Update Fixes Firefox Command Execution Vulnerabilities
- GLSA-200606-12: Mozilla Firefox: Multiple vulnerabilities
- GLSA-200606-21: Mozilla Thunderbird: Multiple vulnerabilities
- GLSA-200703-05: Mozilla Suite: Multiple vulnerabilities
- MDKSA-2006:143: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:143-1: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:145: Updated Firefox packages fix multiple vulnerabilities
- MDKSA-2006:146: Updated Thunderbird packages fix multiple vulnerabilities
- RHSA-2006-0578: seamonkey security update (was mozilla)
- RHSA-2006-0594: seamonkey security update (was mozilla)
- RHSA-2006-0609: seamonkey security update
- RHSA-2006-0610: firefox security update
- RHSA-2006-0611: thunderbird security update
- SA20376: Firefox Multiple Vulnerabilities
- SA20382: Thunderbird Multiple Vulnerabilities
- SA24108: Sun Solaris Mozilla 1.7 Vulnerabilities
- SECTRACK ID: 1016202: Mozilla Firefox Bugs Permit Arbitrary Code Execution, Cross-Site Scripting, and HTTP Response Smuggling
- SECTRACK ID: 1016214: Mozilla Thunderbird Bugs Permit Arbitrary Code Execution, Cross-Site Scripting, and HTTP Response Smuggling
- SUSE-SA:2006:035: Mozilla browser security problems
- US-CERT VU#575969: Mozilla may process content-defined setters on object prototypes with elevated privileges
- USN-296-1: Firefox vulnerabilities
- USN-296-2: Firefox vulnerabilities
- USN-297-1: Thunderbird vulnerabilities
- USN-297-2: Thunderbird extensions update for recent security update
- USN-297-3: Thunderbird vulnerabilities
- USN-323-1: Mozilla vulnerabilities
Reported:
Jun 01, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
