Firefox for Linux Command Line URL Injection security issue

Firefox, Thunderbird, SeaMonkey, Camino, Mozilla, Netscape 6/7/8/9, and all Gecko-based browsers discussion and support forum.
(MozInfo701, Netscape Browser Archive)

Moderators: Antony, Edward, profman, Ramona

Firefox for Linux Command Line URL Injection security issue

Postby J-M » Tue 20 Sep, 2005 8:15 pm

New security issue, rated as Extremely critical (i.e. 5/5) was published recently affecting to Linux versions of Firefox.

Details at http://secunia.com/advisories/16869/ :
The vulnerability is caused due to the shell script used to launch Firefox parsing shell commands that are enclosed within backticks in the URL provided via the command line. This can e.g. be exploited to execute arbitrary shell commands by tricking a user into following a malicious link in an external application which uses Firefox as the default browser (e.g. the mail client Evolution on Red Hat Enterprise Linux 4).

This vulnerability can only be exploited on Unix / Linux based environments.


Version 1.0.6 is confirmed as affected.

Another security company Symantec says Mozilla Suite 1.7.11 is affected too:
http://www.securityfocus.com/bid/14888/info

This will affect to 1.0.7 release timeline. However, Bugzilla entry related to this says it's fixed:
https://bugzilla.mozilla.org/show_bug.cgi?id=307185
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Wed 21 Sep, 2005 4:05 am

This was fixed now in a new 1.0.7 release:

From
http://secunia.com/advisories/16869/

Solution Status: Vendor Patch
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Thu 22 Sep, 2005 5:13 pm

New Mozilla Suite 1.7.12 version release fixes this vulnerability.

To confirm:
From http://secunia.com/advisories/16846/

Solution Status: Vendor Patch
....
Solution:
Update to version 1.7.12.
http://www.mozilla.org/products/mozilla1.x/


More information at:
http://www.mozilla.org/releases/mozilla ... new-issues

Edit: added quoting/J-M :)
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
Last edited by J-M on Thu 22 Sep, 2005 5:14 pm, edited 1 time in total.
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Thu 22 Sep, 2005 5:18 pm

Mozilla Thunderbird installed to Linux is affected too.

From
http://secunia.com/advisories/16901/

The vulnerability is caused due to the shell script used to launch Thunderbird is parsing shell commands that are enclosed within backticks in the URL provided via the command line.
.....
The vulnerability has been confirmed in version 1.0.6 on Fedora Core 4. Other versions and platforms may also be affected.


Secunia's solution (workaround) is:
Do not use Thunderbird as the default mail reader.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby Antony » Thu 22 Sep, 2005 5:39 pm

J-M wrote:Secunia's solution (workaround) is:
Do not use Thunderbird as the default mail reader.
hmm, interesting solution.
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412.7 (KHTML, like Gecko) Safari/412.5
User avatar
Antony
diamond member
diamond member
 
Posts: 14343
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby J-M » Thu 22 Sep, 2005 8:10 pm

Mozilla Foundation has more instructions:

Do not click on links in spam or other mail from people you don't know. Do not use the affected programs as the default handler for URLs. Upgrade to the fixed versions.


Source:
http://www.mozilla.org/security/announc ... 05-59.html
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Fri 30 Sep, 2005 6:07 pm

This was fixed in new Thunderbird 1.0.7, let's wait confirmation at http://www.mozilla.org/projects/securit ... rbird1.0.7 page in the near future.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby J-M » Fri 30 Sep, 2005 6:10 pm

Admins, is it possible to add a short description like 'Affects to Suite and Thunderbird' too to this thread? :)
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi-FI; rv:1.7.10) Gecko/20050717 (No IDN) Firefox/1.0.6
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland


Return to Firefox, SeaMonkey and Netscape

Who is online

Registered users: Google [Bot], Yahoo [Bot]