Firefox "wyciwyg://" Handler Vulnerability

Firefox, Thunderbird, SeaMonkey, Camino, Mozilla, Netscape 6/7/8/9, and all Gecko-based browsers discussion and support forum.
(MozInfo701, Netscape Browser Archive)

Moderators: Antony, Edward, profman, Ramona

Firefox "wyciwyg://" Handler Vulnerability

Postby Ramona » Tue 10 Jul, 2007 3:35 pm

Firefox "wyciwyg://" Handler Vulnerability

Secunia Advisory: SA25990
Release Date: 2007-07-10

Critical: Less critical
Impact: Spoofing

Exposure of sensitive information
Where: From remote
Solution Status: Unpatched

Software: Mozilla Firefox 2.0.x

Description:
Michal Zalewski has discovered a vulnerability in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information and conduct spoofing attacks.

The vulnerability is caused due to an error in the handling of the "wyciwyg://" URI handler. This can be exploited to access or spoof contents from a previously cached web site e.g. via HTTP 302 redirects when a user visits a malicious web page.

The vulnerability is confirmed in version 2.0.0.4. Other versions may also be affected.

Solution:
Do not browse untrusted web sites.

Provided and/or discovered by:
Michal Zalewski

Original Advisory:
http://lcamtuf.coredump.cx/ffcache/
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4
User avatar
Ramona
Moderator
Moderator
 
Posts: 2376
Joined: Wed 19 Jun, 2002 3:50 pm
Location: Midwest USA

Postby Antony » Thu 19 Jul, 2007 2:00 am

This vulnerability is addressed in [sdt=13649]Firefox 2.0.0.5[/sdt].

Mozilla Foundation Security Advisory 2007-24
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4
User avatar
Antony
diamond member
diamond member
 
Posts: 14510
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia


Return to Firefox, SeaMonkey and Netscape

Who is online

Registered users: Google [Bot], Google Feedfetcher