Executive Summary
| Summary | |
|---|---|
| Title | Firefox 3.5 and Xulrunner 1.9.1 regression |
| Informations | |||
|---|---|---|---|
| Name | USN-878-1 | First vendor Publication | 2010-01-08 |
| Vendor | Ubuntu | Last vendor Modification | 2010-01-08 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
A security issue affects the following Ubuntu releases: Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.10: firefox-3.5 3.5.7+nobinonly-0ubuntu0.9.10.1 xulrunner-1.9.1 1.9.1.7+nobinonly-0ubuntu0.9.10.1 After a standard system upgrade you need to restart Firefox and any applications that use xulrunner to effect the necessary changes. Details follow: USN-874-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream changes introduced a regression when using NTLM authentication. This update fixes the problem and added additional stability fixes. We apologize for the inconvenience. Original advisory details: Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and David James discovered several flaws in the browser and JavaScript engines of Firefox. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986) Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox. If an NTLM authenticated user visited a malicious website, a remote attacker could send requests to other applications, authenticated as the user. (CVE-2009-3983) Jonathan Morgan discovered that Firefox did not properly display SSL indicators under certain circumstances. This could be used by an attacker to spoof an encrypted page, such as in a phishing attack. (CVE-2009-3984) Jordi Chancel discovered that Firefox did not properly display invalid URLs for a blank page. If a user were tricked into accessing a malicious website, an attacker could exploit this to spoof the location bar, such as in a phishing attack. (CVE-2009-3985) David Keeler, Bob Clary, and Dan Kaminsky discovered several flaws in third party media libraries. If a user were tricked into opening a crafted media file, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3388, CVE-2009-3389) |
Original Source
| Url : http://www.ubuntu.com/usn/USN-878-1 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-399 | Resource Management Errors |
| CWE-189 | Numeric Errors |
| CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:8009 | |||
| Oval ID: | oval:org.mitre.oval:def:8009 | ||
| Title: | Mozilla Firefox and SeaMonkey 'liboggplay' Media Library Remote Memory Corruption Vulnerabilities | ||
| Description: | liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3388 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:7967 | |||
| Oval ID: | oval:org.mitre.oval:def:7967 | ||
| Title: | Mozilla Firefox and SeaMonkey Theora Video Library Remote Integer Overflow Vulnerability | ||
| Description: | Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3389 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:8487 | |||
| Oval ID: | oval:org.mitre.oval:def:8487 | ||
| Title: | Mozilla Firefox and SeaMonkey Multiple Remote Memory Corruption Vulnerabilities | ||
| Description: | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3979 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:10956 | |||
| Oval ID: | oval:org.mitre.oval:def:10956 | ||
| Title: | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | ||
| Description: | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-3979 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:8503 | |||
| Oval ID: | oval:org.mitre.oval:def:8503 | ||
| Title: | Mozilla Firefox 3.5 and SeaMonkey Multiple Remote Memory Corruption Vulnerabilities | ||
| Description: | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3980 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:8434 | |||
| Oval ID: | oval:org.mitre.oval:def:8434 | ||
| Title: | Mozilla Firefox 3.5 JavaScript Engine Multiple Remote Memory Corruption Vulnerabilities | ||
| Description: | Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3982 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:8240 | |||
| Oval ID: | oval:org.mitre.oval:def:8240 | ||
| Title: | Mozilla Firefox and SeaMonkey NTLM Credential Reflection Authentication Bypass Vulnerability | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3983 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:10047 | |||
| Oval ID: | oval:org.mitre.oval:def:10047 | ||
| Title: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user. | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-3983 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9791 | |||
| Oval ID: | oval:org.mitre.oval:def:9791 | ||
| Title: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body. | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-3984 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:8379 | |||
| Oval ID: | oval:org.mitre.oval:def:8379 | ||
| Title: | Mozilla Firefox and Sea Monkey Insecure Protocol Location Bar Spoofing Vulnerability | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3984 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:9911 | |||
| Oval ID: | oval:org.mitre.oval:def:9911 | ||
| Title: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654. | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-3985 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:8480 | |||
| Oval ID: | oval:org.mitre.oval:def:8480 | ||
| Title: | Mozilla Firefox and Sea Monkey Content Injection Spoofing Vulnerability | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3985 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:8489 | |||
| Oval ID: | oval:org.mitre.oval:def:8489 | ||
| Title: | Mozilla Firefox 'window.opener' Property Chrome Privilege Escalation Vulnerability | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-3986 |
Version: | 3 |
| Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows 7 |
Product(s): | Mozilla Firefox Mozilla Seamonkey |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:11568 | |||
| Oval ID: | oval:org.mitre.oval:def:11568 | ||
| Title: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property. | ||
| Description: | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-3986 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
ExploitDB Exploits
| id | Description |
|---|---|
| 2009-12-18 | Mozilla Firefox Location Bar Spoofing Vulnerability |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 61103 | Mozilla Multiple Browsers libtheora Video Library Unspecified DoS |
| 61102 | Mozilla Multiple Browsers libtheora Video Library Dimension Handling Overflow |
| 61101 | Mozilla Multiple Browser NTLM Reflection Authentication Credential Disclosure |
| 61100 | Mozilla Multiple Browsers document.location 204 Response SSL Status Spoofing |
| 61099 | Mozilla Multiple Browsers document.location Blank Page Content Spoofing |
| 61098 | Mozilla Multiple Browsers liboggplay Multiple Unspecified Code Execution |
| 61097 | Mozilla Firefox Browser Engine Multiple Unspecified Memory Corruption |
| 61095 | Mozilla Multiple Browsers Chrome window.opener Property Privilege Escalation |
| 61094 | Mozilla Firefox Browser Engine Multiple Unspecified Memory Corruption |
| 61093 | Mozilla Multiple Products JavaScript Engine Multiple Unspecified Memory Corru... |

USN-878-1
(Critical)
(High)
(Medium)







