Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2005.134.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-134-1)
Summary:The remote host is missing an update for the 'mozilla-firefox' package(s) announced via the USN-134-1 advisory.
Description:Summary:
The remote host is missing an update for the 'mozilla-firefox' package(s) announced via the USN-134-1 advisory.

Vulnerability Insight:
It was discovered that a malicious website could inject arbitrary
scripts into a target site by loading it into a frame and navigating
back to a previous Javascript URL that contained an eval() call. This
could be used to steal cookies or other confidential data from the
target site. If the target site is allowed to raise the install
confirmation dialog in Firefox then this flaw even allowed the
malicious site to execute arbitrary code with the privileges of the
Firefox user. By default only the Mozilla Update site is allowed to
attempt software installation, however, users can permit this for
additional sites. (MFSA 2005-42)

Michael Krax, Georgi Guninski, and L. David Baron found that the
security checks that prevent script injection could be bypassed by
wrapping a javascript: url in another pseudo-protocol like
'view-source:' or 'jar:'. (CAN-2005-1531)

A variant of the attack described in CAN-2005-1160 (see USN-124-1) was
discovered. Additional checks were added to make sure Javascript eval
and Script objects are run with the privileges of the context that
created them, not the potentially elevated privilege of the context
calling them. (CAN-2005-1532)

Note: These flaws also apply to Ubuntu 5.04's Mozilla, and to the
Ubuntu 4.10 versions of Firefox and Mozilla. These will be fixed soon.

Affected Software/OS:
'mozilla-firefox' package(s) on Ubuntu 5.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-1531
1013962
http://securitytracker.com/id?1013962
1013963
http://securitytracker.com/id?1013963
13641
http://www.securityfocus.com/bid/13641
15495
http://www.securityfocus.com/bid/15495
ADV-2005-0530
http://www.vupen.com/english/advisories/2005/0530
RHSA-2005:434
http://www.redhat.com/support/errata/RHSA-2005-434.html
RHSA-2005:435
http://www.redhat.com/support/errata/RHSA-2005-435.html
SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://www.mozilla.org/security/announce/mfsa2005-43.html
oval:org.mitre.oval:def:100015
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100015
oval:org.mitre.oval:def:10351
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10351
Common Vulnerability Exposure (CVE) ID: CVE-2005-1532
1013964
http://securitytracker.com/id?1013964
1013965
http://securitytracker.com/id?1013965
13645
http://www.securityfocus.com/bid/13645
19823
http://secunia.com/advisories/19823
RHSA-2005:601
http://www.redhat.com/support/errata/RHSA-2005-601.html
SUSE-SA:2006:022
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.mozilla.org/security/announce/mfsa2005-44.html
oval:org.mitre.oval:def:100014
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100014
oval:org.mitre.oval:def:10791
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10791
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.