Multiple Mozilla products XUL popup tab spoofing
| firefox-xul-popup-spoofing (41454) |
Description:
Multiple Mozilla products, including Firefox and SeaMonkey are vulnerable to spoofing, caused by the improper handling of XUL popups. By persuading a victim to visit a malicious Web site that creates a borderless XUL popup containing a spoofed form element when opened in a background tab, a remote attacker could exploit this vulnerability to conduct phishing attacks on Web sites viewed in an active tab.
Platforms Affected:
- Canonical, Ubuntu 6.06 LTS
- Canonical, Ubuntu 6.10
- Canonical, Ubuntu 7.04
- Canonical, Ubuntu 7.10
- Debian, Debian Linux 4.0
- Mandriva, Corporate Server 3.0 X86_64
- Mandriva, Corporate Server 3.0
- Mandriva, Corporate Server 4.0
- Mandriva, Corporate Server 4.0 X86_64
- Mandriva, Linux 2007.1 X86_64
- Mandriva, Linux 2007.1
- Mandriva, Linux 2008.0
- Mandriva, Linux 2008.0 X86_64
- Mozilla, Firefox 2.0
- Mozilla, Firefox 2.0 Beta2
- Mozilla, Firefox 2.0 rc1
- Mozilla, Firefox 2.0 rc3
- Mozilla, Firefox 2.0 rc2
- Mozilla, Firefox 2.0 Beta1
- Mozilla, Firefox 2.0.0.1
- Mozilla, Firefox 2.0.0.10
- Mozilla, Firefox 2.0.0.11
- Mozilla, Firefox 2.0.0.12
- Mozilla, Firefox 2.0.0.2
- Mozilla, Firefox 2.0.0.3
- Mozilla, Firefox 2.0.0.4
- Mozilla, Firefox 2.0.0.5
- Mozilla, Firefox 2.0.0.6
- Mozilla, Firefox 2.0.0.7
- Mozilla, Firefox 2.0.0.8
- Mozilla, Firefox 2.0.0.9
- Mozilla, SeaMonkey 1.1
- Mozilla, SeaMonkey 1.1 Beta
- Mozilla, SeaMonkey 1.1.0
- Mozilla, SeaMonkey 1.1.1
- Mozilla, SeaMonkey 1.1.2
- Mozilla, SeaMonkey 1.1.3
- Mozilla, SeaMonkey 1.1.4
- Mozilla, SeaMonkey 1.1.5
- Mozilla, SeaMonkey 1.1.6
- Mozilla, SeaMonkey 1.1.7
- Mozilla, SeaMonkey 1.1.8
- Novell, Linux Desktop 9
- Novell, OpenSUSE 10.2
- Novell, OpenSUSE 10.3
- Novell, SLE SDK 10 SP1
- Novell, SUSE Linux Enterprise Desktop 10 SP1
- Novell, SUSE Linux Enterprise Server 10
- Novell, SUSE Linux Enterprise Server 10 SP1
- RedHat, Enterprise Linux 2.1 AS
- RedHat, Enterprise Linux 2.1 ES
- RedHat, Enterprise Linux 2.1 WS
- RedHat, Enterprise Linux 3 ES
- RedHat, Enterprise Linux 3 WS
- RedHat, Enterprise Linux 3 AS
- RedHat, Enterprise Linux 3 Desktop
- RedHat, Enterprise Linux 4 Desktop
- RedHat, Enterprise Linux 4 AS
- RedHat, Enterprise Linux 4 ES
- RedHat, Enterprise Linux 4 WS
- RedHat, Enterprise Linux 5 Client
- RedHat, Enterprise Linux 5 Client Workstation
- RedHat, Enterprise Linux 5
- RedHat, Enterprise Linux Optional Productivity Applications 5 Server
- RedHat, Linux Advanced Workstation 2.1 Itanium
- Sun, OpenSolaris 2008.5 x86
- Sun, OpenSolaris 2008.5 SPARC
- Sun, Solaris 10 SPARC
- Sun, Solaris 10 x86
- SuSE, SLE SDK 10
Remedy:
Refer to MFSA 2008-19 for patch, upgrade or suggested workaround information. See References.
For other distributions:
Apply the appropriate update for your system. See References.
Consequences:
Gain Access
References:
- MFSA 2008-19, XUL popup spoofing variant (cross-tab popups) at http://www.mozilla.org/security/announce/2008/mfsa2008-19.html.
- Sun Alert ID: 238492, Multiple Security Vulnerabilities in Solaris 10 Firefox may Allow Execution of Arbitrary Code and Access to Unauthorized Data at http://sunsolve.sun.com/search/document.do?assetkey=1-66-238492-1.
- ASA-2008-142: firefox security update (RHSA-2008-0207)
- ASA-2008-143: seamonkey security update (RHSA-2008-0208)
- ASA-2008-146: thunderbird security update (RHSA-2008-0209)
- BID-28448: Mozilla Thunderbird/Seamonkey/Firefox 2.0.0.12 Multiple Remote Vulnerabilities
- CVE-2008-1241: GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.
- DSA-1532: xulrunner -- several vulnerabilities
- DSA-1534: iceape -- several vulnerabilities
- DSA-1535: iceweasel -- several vulnerabilities
- FrSIRT/ADV-2008-0998: Mozilla Firefox and SeaMonkey Multiple Remote Code Execution Issues
- MDVSA-2008:080: Updated Firefox packages fix multiple vulnerabilities
- RHSA-2008-0207: Critical: firefox security update
- RHSA-2008-0208: Critical: seamonkey security update
- RHSA-2008-0209: Moderate: thunderbird security update
- SA29526: Mozilla Firefox Multiple Vulnerabilities
- SA29547: Mozilla SeaMonkey Multiple Vulnerabilities
- SA30620: Sun Solaris Firefox Multiple Vulnerabilities
- SECTRACK ID: 1019700: Mozilla Firefox XUL Popup Bug Lets Remote Users Spoof Tabbed Pages
- SUSE-SA:2008:019: Mozilla Firefox security update
- USN-592-1: Firefox vulnerabilities
Reported:
Mar 25, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
