Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2005.149.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-149-1)
Summary:The remote host is missing an update for the 'mozilla-firefox' package(s) announced via the USN-149-1 advisory.
Description:Summary:
The remote host is missing an update for the 'mozilla-firefox' package(s) announced via the USN-149-1 advisory.

Vulnerability Insight:
Secunia.com reported that one of the recent security patches in
Firefox reintroduced the frame injection patch that was originally
known as CAN-2004-0718. This allowed a malicious web site to spoof the
contents of other web sites. (CAN-2005-1937)

In several places the browser user interface did not correctly
distinguish between true user events, such as mouse clicks or
keystrokes, and synthetic events genenerated by web content. This
could be exploited by malicious web sites to generate e. g. mouse
clicks that install malicious plugins. Synthetic events are now
prevented from reaching the browser UI entirely. (CAN-2005-2260)

Scripts in XBL controls from web content continued to be run even when
Javascript was disabled. This could be combined with most script-based
exploits to attack people running vulnerable versions who thought
disabling Javascript would protect them. (CAN-2005-2261)

Matthew Mastracci discovered a flaw in the addons installation
launcher. By forcing a page navigation immediately after calling the
install method a callback function could end up running in the context
of the new page selected by the attacker. This callback script could
steal data from the new page such as cookies or passwords, or perform
actions on the user's behalf such as make a purchase if the user is
already logged into the target site. However, the default settings
allow only [link moved to references] to bring up this install dialog.
This could only be exploited if users have added untrustworthy sites
to the installation allowlist, and if a malicious site can convince
you to install from their site. (CAN-2005-2263)

Kohei Yoshino discovered a Javascript injection vulnerability in the
sidebar. Sites can use the _search target to open links in the Firefox
sidebar. A missing security check allowed the sidebar to inject
'data:' URLs containing scripts into any page open in the browser.
This could be used to steal cookies, passwords or other sensitive
data. (CAN-2005-2264)

The function for version comparison in the addons installer did not
properly verify the type of its argument. By passing specially crafted
Javascript objects to it, a malicious web site could crash the browser
and possibly even execute arbitrary code with the privilege of the
user account Firefox runs in. (CAN-2005-2265)

A child frame can call top.focus() even if the framing page comes from
a different origin and has overridden the focus() routine. Andreas
Sandblad discovered that the call is made in the context of the child
frame. This could be exploited to steal cookies and passwords from the
framed page, or take actions on behalf of a signed-in user. However,
web sites with above properties are not very common. (CAN-2005-2266)

Several media players, for example Flash and QuickTime, support
scripted content with the ability to open URLs in the default browser.
The default behavior for Firefox was to replace the ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'mozilla-firefox' package(s) on Ubuntu 5.04.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-1937
BugTraq ID: 14242
http://www.securityfocus.com/bid/14242
Debian Security Information: DSA-777 (Google Search)
http://www.debian.org/security/2005/dsa-777
Debian Security Information: DSA-810 (Google Search)
http://www.debian.org/security/2005/dsa-810
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100007
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10633
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A759
http://www.redhat.com/support/errata/RHSA-2005-586.html
http://www.redhat.com/support/errata/RHSA-2005-587.html
http://secunia.com/advisories/15601
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101952-1
SuSE Security Announcement: SUSE-SA:2005:045 (Google Search)
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
SuSE Security Announcement: SUSE-SR:2005:018 (Google Search)
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://www.vupen.com/english/advisories/2005/1075
Common Vulnerability Exposure (CVE) ID: CVE-2005-2260
14242
16043
http://secunia.com/advisories/16043
16044
http://secunia.com/advisories/16044
16059
http://secunia.com/advisories/16059
ADV-2005-1075
DSA-810
FLSA:160202
P-252
http://www.ciac.org/ciac/bulletins/p-252.shtml
RHSA-2005:586
RHSA-2005:587
SUSE-SA:2005:045
SUSE-SR:2005:018
http://bugzilla.mozilla.org/show_bug.cgi?id=289940
http://www.mozilla.org/security/announce/mfsa2005-45.html
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
oval:org.mitre.oval:def:100013
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100013
oval:org.mitre.oval:def:10132
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10132
oval:org.mitre.oval:def:1226
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1226
oval:org.mitre.oval:def:742
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A742
Common Vulnerability Exposure (CVE) ID: CVE-2005-2261
19823
http://secunia.com/advisories/19823
RHSA-2005:601
http://www.redhat.com/support/errata/RHSA-2005-601.html
SUSE-SA:2006:022
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.mozilla.org/security/announce/mfsa2005-46.html
https://bugzilla.mozilla.org/show_bug.cgi?id=292589
https://bugzilla.mozilla.org/show_bug.cgi?id=292591
oval:org.mitre.oval:def:100012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100012
oval:org.mitre.oval:def:10947
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10947
oval:org.mitre.oval:def:1348
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1348
oval:org.mitre.oval:def:808
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A808
Common Vulnerability Exposure (CVE) ID: CVE-2005-2263
http://www.mozilla.org/security/announce/mfsa2005-48.html
https://bugzilla.mozilla.org/show_bug.cgi?id=293331
oval:org.mitre.oval:def:100010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100010
oval:org.mitre.oval:def:100016
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100016
oval:org.mitre.oval:def:11629
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11629
oval:org.mitre.oval:def:1281
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1281
oval:org.mitre.oval:def:1311
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1311
Common Vulnerability Exposure (CVE) ID: CVE-2005-2264
http://www.mozilla.org/security/announce/mfsa2005-49.html
https://bugzilla.mozilla.org/show_bug.cgi?id=294074
oval:org.mitre.oval:def:100009
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100009
oval:org.mitre.oval:def:9887
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9887
Common Vulnerability Exposure (CVE) ID: CVE-2005-2265
http://www.mozilla.org/security/announce/mfsa2005-50.html
https://bugzilla.mozilla.org/show_bug.cgi?id=295854
oval:org.mitre.oval:def:100008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100008
oval:org.mitre.oval:def:10397
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10397
oval:org.mitre.oval:def:417
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A417
oval:org.mitre.oval:def:781
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A781
Common Vulnerability Exposure (CVE) ID: CVE-2005-2266
15549
http://secunia.com/advisories/15549
15551
http://secunia.com/advisories/15551
15553
http://secunia.com/advisories/15553
http://www.mozilla.org/security/announce/mfsa2005-52.html
mozilla-frame-topfocus-xss(21332)
https://exchange.xforce.ibmcloud.com/vulnerabilities/21332
oval:org.mitre.oval:def:100107
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100107
oval:org.mitre.oval:def:10712
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10712
oval:org.mitre.oval:def:1415
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1415
oval:org.mitre.oval:def:773
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A773
Common Vulnerability Exposure (CVE) ID: CVE-2005-2267
1014469
http://securitytracker.com/id?1014469
http://www.mozilla.org/security/announce/mfsa2005-53.html
https://bugzilla.mozilla.org/show_bug.cgi?id=298255
oval:org.mitre.oval:def:100006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100006
oval:org.mitre.oval:def:1073
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1073
oval:org.mitre.oval:def:11334
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11334
oval:org.mitre.oval:def:1172
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1172
Common Vulnerability Exposure (CVE) ID: CVE-2005-2268
15489
http://secunia.com/advisories/15489
http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/
http://www.mozilla.org/security/announce/mfsa2005-54.html
oval:org.mitre.oval:def:100005
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100005
oval:org.mitre.oval:def:10517
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10517
oval:org.mitre.oval:def:1268
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1268
oval:org.mitre.oval:def:1313
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1313
Common Vulnerability Exposure (CVE) ID: CVE-2005-2269
http://www.mozilla.org/security/announce/mfsa2005-55.html
https://bugzilla.mozilla.org/show_bug.cgi?id=298892
oval:org.mitre.oval:def:100004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100004
oval:org.mitre.oval:def:100011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100011
oval:org.mitre.oval:def:1258
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1258
oval:org.mitre.oval:def:729
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A729
oval:org.mitre.oval:def:9777
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9777
Common Vulnerability Exposure (CVE) ID: CVE-2005-2270
1014470
http://securitytracker.com/id?1014470
VU#652366
http://www.kb.cert.org/vuls/id/652366
http://www.mozilla.org/security/announce/mfsa2005-56.html
https://bugzilla.mozilla.org/show_bug.cgi?id=294795
https://bugzilla.mozilla.org/show_bug.cgi?id=294799
https://bugzilla.mozilla.org/show_bug.cgi?id=295011
https://bugzilla.mozilla.org/show_bug.cgi?id=296397
oval:org.mitre.oval:def:100003
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100003
oval:org.mitre.oval:def:11751
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11751
oval:org.mitre.oval:def:550
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A550
oval:org.mitre.oval:def:817
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A817
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.