Note: This is an archival copy of Security Sun Alert 256408 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1020330.1.
Article ID : 1020330.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2009-04-06
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

Multiple Security Vulnerabilities in Firefox Versions Before 2.0.0.19 May Allow Execution of Arbitrary Code or Access to Unauthorized Data



Category
Security

Release Phase
Resolved

Bug Id
6786624

Product
Firefox 2.0
Solaris 10 Operating System
OpenSolaris

Date of Resolved Release
07-Apr-2009

Multiple Security Vulnerabilities in Firefox Versions Before 2.0.0.19 May Allow Execution of Arbitrary Code or Access to Unauthorized Data

1. Impact

Multiple security vulnerabilities in firefox(1) versions prior to 2.0.0.19 shipped with Solaris 10 may allow an unprivileged remote user to execute arbitrary code on the system where firefox(1) is being run, gain unauthorized access to sensitive data, perform Cross-Site Scripting (XSS) attacks to bypass access controls, read or modify data in other web sites, or inject code into web pages to obtain sensitive data from the user or information stored in cookies

Certain vulnerabilities may also allow a user to crash the firefox(1) application which is a type of Denial of Service (DoS).

The following URL provides additional details about the vulnerabilities addressed in Firefox versions prior to 2.0.0.19:

http://www.mozilla.org/security/known-vulnerabilities/firefox20.html

The following CVEs correspond to the Mozilla Foundation Security Advisories referenced in the above URL for Firefox versions 2.0.0.15 through 2.0.0.19:

CVE-2008-2800  CVE-2008-2801  CVE-2008-2802  CVE-2008-2803  CVE-2008-2805
CVE-2008-2807  CVE-2008-2808  CVE-2008-2809  CVE-2008-2811  CVE-2008-2785 
CVE-2008-2933  CVE-2008-2934  CVE-2008-0016  CVE-2008-3835  CVE-2008-3836 
CVE-2008-3837  CVE-2008-4058  CVE-2008-4059  CVE-2008-4060  CVE-2008-4061 
CVE-2008-4062  CVE-2008-4063  CVE-2008-4064  CVE-2008-4065  CVE-2008-4066 
CVE-2008-4067  CVE-2008-4068  CVE-2008-4069  CVE-2008-4070  CVE-2008-4582 
CVE-2008-5012  CVE-2008-5013  CVE-2008-5014  CVE-2008-5015  CVE-2008-5016 
CVE-2008-5017  CVE-2008-5018  CVE-2008-5019  CVE-2008-0017  CVE-2008-5021 
CVE-2008-5022  CVE-2008-5023  CVE-2008-5024  CVE-2008-5500  CVE-2008-5501 
CVE-2008-5502  CVE-2008-5503  CVE-2008-5504  CVE-2008-5505  CVE-2008-5506 
CVE-2008-5507  CVE-2008-5508  CVE-2008-5510  CVE-2008-5511  CVE-2008-5512 
CVE-2008-5513

2. Contributing Factors

These issues can occur in the following releases:

SPARC Platform
  • Firefox 2.0 for Solaris 10 without patch 125539-06
  • OpenSolaris based upon builds snv_89 through snv_94
x86 Platform
  • Firefox 2.0 for Solaris 10 without patch 125540-06
  • OpenSolaris based upon builds snv_89 through snv_94
Notes:

1. Solaris 8 and Solaris 9 do not ship Firefox and therefore are not affected by these issues.
2. Firefox 2.x is no longer shipped with OpenSolaris starting with snv_95 which includes Firefox 3.x.

3. Symptoms

There are no predictable symptoms that would indicate the described issues have been exploited.

4. Workaround

For the following Mozilla Foundation Security Advisories there is a workaround of disabling Java Script:


For Mozilla Foundation Security Advisory MFSA 2008-35, the following is a workaround:

This attack only works if the user is using another internet-connected application with Firefox not running. Using Firefox, or making sure it is at least running, prevents this attack.

For Mozilla Foundation Security Advisory MFSA 2008-40, the following is a workaround:

1. Open Options/Preferences dialog
2. Go to the "Content" tab
3. Click the "Advanced..." button on the same line as the "Enable JavaScript" checkbox
4. UN-check the "Move or resize existing windows" box.

5. Resolution

These issues are addressed in the following releases:

SPARC Platform
  • Firefox 2.0 for Solaris 10 with patch 125539-06 or later
  • OpenSolaris based upon builds snv_95 or later
x86 Platform
  • Firefox 2.0 for Solaris 10 with patch 125540-06 or later
  • OpenSolaris based upon builds snv_95 or later
For more information on Security Sun Alerts, see 1009886.1.

This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may contain information provided by third parties. The issues described in this Sun Alert notification may or may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the purposes contemplated by these agreements.

Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.

References

125539-06
125540-06





Attachments
This solution has no attachment