Vulnerability Note VU#405092

Mozilla products allows the src attribute in an img element to be changed to a JavaScript URI

Original Release date: 18 Jan 2007 | Last revised: 05 Mar 2007

Overview

Mozilla products contain a cross-site scripting vulnerability due to a vulnerability in the way IMG elements are loaded.

Description

A vulnerability in the way Mozilla products load IMG elements in a frame may cause a cross-site script injection. According to Mozilla Foundation Security Advisory 2006-72:

    ... the src attribute of an IMG element loaded in a frame could be changed to a javascript: URI that was able to bypass the protections against cross-site script (XSS) injection. The injected script could steal credentials and financial data, or perform destructive actions on behalf of a logged-in user.

Impact

By convincing a victim to view an HTML document (web page), an attacker could evaluate script in a different security domain than the one containing the attacker's document. The attacker could read or modify data in other web sites (read cookies/content, modify/create content, etc.). If the script is evaluated with chrome privileges, an attacker could execute arbitrary commands on the user's system.

Solution

Apply an update
According to the Mozilla Foundation Security Advisory 2006-72, this vulnerability is addressed in Firefox 2.0.0.1, Firefox 1.5.0.9, Thunderbird 1.5.0.9, and SeaMonkey 1.0.7.

Disable JavaScript


For instructions on how to disable JavaScript in Firefox, please refer to the Firefox section of the Securing Your Web Browser document.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Debian GNU/LinuxAffected-05 Mar 2007
Fedora ProjectAffected-18 Jan 2007
Gentoo LinuxAffected-18 Jan 2007
Mandriva, Inc.Affected-18 Jan 2007
MozillaAffected-21 Dec 2006
Red Hat, Inc.Affected-18 Jan 2007
rPathAffected-18 Jan 2007
Slackware Linux Inc.Affected-18 Jan 2007
SUSE LinuxAffected-18 Jan 2007
UbuntuAffected-18 Jan 2007
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was reported in Mozilla Foundation Security Advisory 2006-72. Mozilla credits moz_bug_r_a4 with providing information about this issue.

This document was written by Chris Taschner.

Other Information

  • CVE IDs: CVE-2006-6503
  • Date Public: 19 Dec 2006
  • Date First Published: 18 Jan 2007
  • Date Last Updated: 05 Mar 2007
  • Severity Metric: 10.26
  • Document Revision: 25

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.