| Múltiplas vulnerabilidades em produtos Mozilla |
|
|
| Sistemas Operativos Implicados: | Indefinido |
| Aplicações Implicadas: | Mozilla |
I.Description
A Multiple vulnerabilities have been
reported in Mozilla Firefox, which can be exploited by malicious people
to gain knowledge of certain information, conduct cross-site scripting
attacks, and potentially compromise a user"s system.
1)Various errors in the layout engine and JavaScript engine can be
exploited to cause memory corruption and some may potentially allow
execution of arbitrary code.
2) An error when reducing the CPU"s floating point precision, which may
happen on Windows when loading a plugin creating a Direct3D device, may
cause the "js_dtoa()" function to not exit and instead cause a memory
corruption.
3) A boundary error when setting the cursor to a Windows bitmap using
the CSS cursor property can be exploited to cause a heap-based buffer
overflow.
4) An unspecified error in the "watch()" JavaScript function can be
exploited to execute arbitrary code.
5) An error in LiveConnect causes an already freed object to be used
and may potentially allow execution of arbitrary code.
6) An error in the handling of the "src" attribute of IMG elements
loaded in a frame can be exploited to change the attribute to a
"javascript:" URI. This allows execution of arbitrary HTML and script
code in a user"s browser session.
7) An error within the handling of SVG comment objects can be exploited
to cause a memory corruption and allows execution of arbitrary code by
appending an SVG comment object from one document into another type of
document (e.g. HTML).
8) The "Feed Preview" feature of Firefox 2.0 may leak feed-browsing
habits to websites when retrieving the icons of installed web-based
feed viewers.
9) A Function prototype regression in Firefox 2.0 can be exploited to
execute arbitrary HTML and script code in a user"s browser session.
III. References
O CERT.PT tem como missão contribuir para o esforço de cibersegurança nacional nomeadamente no tratamento e coordenação da resposta a incidentes, na produção de alertas e recomendações de segurança e na promoção de uma cultura de segurança em Portugal.
Av. do Brasil 101
1700-066 Lisboa
Portugal
Tel: +351 218440177 (9h30-12h30, 14h00-17h30; GMT)
Fax: +351 218472167
email:
pgp: 342A 17BA DF71 E193 6871 0357 8BDE A247 C523 AAE7