2014-08-06 09:00:40 +04:00
|
|
|
---
|
2014-07-15 19:04:48 +04:00
|
|
|
announced: September 23, 2008
|
2014-08-06 09:00:40 +04:00
|
|
|
fixed_in:
|
|
|
|
- Firefox 3.0.2
|
|
|
|
- Firefox 2.0.0.17
|
|
|
|
- Thunderbird 2.0.0.17
|
|
|
|
- SeaMonkey 1.1.12
|
2014-07-15 19:04:48 +04:00
|
|
|
impact: Critical
|
|
|
|
reporter: moz_bug_r_a4, Olli Pettay
|
|
|
|
title: Privilege escalation via XPCnativeWrapper pollution
|
2014-08-06 09:00:40 +04:00
|
|
|
---
|
2014-07-12 00:08:09 +04:00
|
|
|
|
|
|
|
<h3>Description</h3>
|
|
|
|
|
|
|
|
<p>Mozilla security researcher <strong>moz_bug_r_a4</strong> reported a
|
|
|
|
series of vulnerabilities by which page content can pollute
|
|
|
|
XPCNativeWrappers and have arbitrary code run with chrome privileges.
|
|
|
|
One variant reported by moz_bug_r_a4 only affected Firefox 2.</p>
|
|
|
|
|
|
|
|
<p>Mozilla developer <strong>Olli Pettay</strong> reported that XSLT can
|
|
|
|
create documents which do not have script handling objects. moz_bug_r_a4
|
|
|
|
also reported that <code>document.loadBindingDocument()</code> returns a
|
|
|
|
document that does not have a script handling object. These issues could
|
|
|
|
also be used by an attacker to run arbitrary script with chrome privileges.</p>
|
|
|
|
|
|
|
|
<p class="note">Thunderbird shares the browser engine with Firefox and
|
|
|
|
could be vulnerable if JavaScript were to be enabled in mail. This is not
|
|
|
|
the default setting and we strongly discourage users from running
|
|
|
|
JavaScript in mail.</p>
|
|
|
|
|
|
|
|
<h3>Workaround</h3>
|
|
|
|
|
|
|
|
<p>Disable JavaScript until a version containing these fixes can be installed.</p>
|
|
|
|
|
|
|
|
<h3>References</h3>
|
|
|
|
|
|
|
|
<ul>
|
|
|
|
<li><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=444073,444075,444077">XPCnativeWrapper pollution bugs</a></li>
|
|
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4058">CVE-2008-4058</a></li>
|
|
|
|
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=419848">XPCnativeWrapper pollution (Firefox 2)</a></li>
|
|
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4059">CVE-2008-4059</a></li>
|
|
|
|
<li><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=448548,451037">Documents without script handling objects</a></li>
|
|
|
|
<li><a class="ex-ref" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4060">CVE-2008-4060</a></li>
|
|
|
|
</ul>
|
|
|
|
|
|
|
|
|
|
|
|
|