Overview
Mozilla Firefox may execute JavaScript contained within the IconURL parameter of InstallTrigger.install() with chrome privileges. This may allow an attacker to execute arbitrary commands on a vulnerable system.
Description
XPInstall XPInstall is a cross-platform software installation method used by Mozilla-based browsers. javascript:eval('alert("Hello world.")') The Problem |
Impact
By convincing a user to view an HTML document (e.g., a web page), an attacker could execute arbitrary commands or code with the privileges of the user. The attacker could take any action as the user. If the user has administrative privileges, the attacker could take complete control of the user's system. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.mozilla.org/security/announce/mfsa2005-42.html
- http://www.mozilla.org/security/announce/mfsa2005-43.html
- http://www.mozilla.org/security/announce/mfsa2005-44.html
- http://www.frsirt.com/english/advisories/2005/0493
- http://secunia.com/advisories/15292/
- http://www.securityfocus.com/archive/1/397817/2005-05-07/2005-05-13/0
- http://greyhatsecurity.org/vulntests/ffrc.htm
- http://www.securitytracker.com/alerts/2005/May/1013913.html
- http://www.securityfocus.com/bid/13544668916
- 6
- http://www.osvdb.org/displayvuln.php?osvdb_id=16185
- https://bugzilla.mozilla.org/show_bug.cgi?id=293302
- https://bugzilla.mozilla.org/show_bug.cgi?id=292691
Acknowledgements
This vulnerability was reported by Paul of Greyhats and Michael Krax. Thanks to Daniel Veditz of the Mozilla Foundation for discussing the vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2005-1477 |
Severity Metric: | 8.57 |
Date Public: | 2005-05-07 |
Date First Published: | 2005-05-10 |
Date Last Updated: | 2005-08-01 14:10 UTC |
Document Revision: | 19 |