1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Mozilla Firefox 3 Multiple Vulnerabilities

Report ID: SA33203
Source: Secunia
Date of Discovery: 17.12.2008
Criticality: Urgent
Affects:
Mozilla Firefox 3.x

Compromise From: From remote
Compromise Type: Security bypass
System access
Exposure of sensitive information
Cross site scripting

Summary

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.

Detailed Description

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to bypass certain security restrictions, disclose sensitive information, conduct cross-site scripting attacks, or potentially compromise a user's system.

1) Multiple errors in the layout and JavaScript engines can be exploited to corrupt memory and potentially execute arbitrary code.

2) An error when processing the "persist" XUL attribute can be exploited to bypass cookie settings and uniquely identify a user in subsequent browsing sessions.

3) Multiple errors can be exploited to bypass the same-origin policy, disclose sensitive information, and execute JavaScript code with chrome privileges.

For more information see vulnerabilities #4 through #10 in:
SA33184

The vulnerabilities are reported in versions prior to 3.0.5.

CVE Reference

CVE-2008-5506
CVE-2008-5512
CVE-2008-5511
CVE-2008-5508
CVE-2008-5501
CVE-2008-5500
CVE-2008-5505
CVE-2008-5513
CVE-2008-5510
CVE-2008-5502
CVE-2008-5507