|
|
|
Vulnerability Note VU#968814Mozilla JavaScript security bypass vulnerabilityOverviewMozilla products fail to properly enforce security restrictions in JavaScript. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code.I. DescriptionAccording to Mozilla Foundation Security Advisory 2006-28:The security check in js_ValueToFunctionObject() can be bypassed by clever use of setTimeout() and the new Firefox 1.5 array method ForEach. shutdown demonstrated how to leverage this into a privilege escalation vulnerability that would allow the installation of malware. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.III. SolutionUpgradeThis issue is fixed in Firefox 1.5.0.2, Thunderbird 1.5.0.2, and SeaMonkey 1.0.1.
References
This vulnerability was reported in Mozilla Foundation Security Advisory 2006-28. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||