CERT-In Advisory
CIAD-2012-0052
Multiple Vulnerabilities in Mozilla Products
Original Issue Date: November 09, 2012
Severity Rating: High
Systems Affected
- Mozilla Firefox before 16.0.2
- Mozilla Firefox ESR 10.x before 10.0.10
- Thunderbird before 16.0.2
- Thunderbird ESR 10.x before 10.0.10
- Mozilla SeaMonkey before 2.13.2
Overview
Multiple vulnerabilities have been reported in Mozilla Products which could be exploited by a remote attacker to conduct cross-site scripting attack or disclose sensitive information.
Description
1. ValueOf() Cross-site scripting (XSS) Vulnerability
(
CVE-2012-4194
)
The Vulnerability occurs while handling the "window.location"object The true value of window.location could be shadowed by user content through the use of the valueOf method which could be combined with some plugins by the remote attacker to execute arbitrary code on the target user's system and cause cross-site scripting (XSS) attack.
2. CheckURL() Cross-site scripting (XSS) Vulnerability
(
CVE-2012-4195
)
The Vulnerability occurs due to the error within the "CheckURL()" function of the "window.location" object. The CheckURL function in window.location could be forced to return the wrong calling document and principal which could allow a remote attacker to perform cross-site scripting (XSS) attack.
3. Same Origin Policy Bypass Vulnerability
(
CVE-2012-4196
)
The Vulnerability exists within security wrappers which could not unwrap the "defaultValue" properly. A remote attackers could bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
Solution
Upgrade to Mozilla firefox version 16.0.2 or 10.0.10
http://www.mozilla.org/en-US/firefox/new/
Upgrade to Mozilla Thunderbird version 10.0.10
http://www.mozilla.org/en-US/thunderbird/
Upgrade to Mozilla SeaMonkey version 2.13.2
http://www.mozilla.org/en-US/seamonkey/
Vendor Information
Mozilla
http://www.mozilla.org/security/announce/2012/mfsa2012-90.html
References
Mozilla
http://www.mozilla.org/security/announce/2012/mfsa2012-90.html
Secunia
http://secunia.com/advisories/51144/
SecurityTracker
http://securitytracker.com/id/1027701
CVE Name
CVE-2012-4194
CVE-2012-4195
CVE-2012-4196
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|