(Netscape Issues Fix) Firefox Lets Remote Users Invoke eval and Script Objects With Elevated Privileges
|
|
SecurityTracker Alert ID: 1014020 |
|
SecurityTracker URL: http://securitytracker.com/id/1014020
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: May 21 2005
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 8.0
|
Description:
A vulnerability was reported in the Firefox web browser. A remote user can cause scripting code to be executed with elevated privileges. The Netscape browser is affected.
A remote user can create HTML that can cause privileged code to invoke eval() or Script() objects with user-supplied data. Scripts in the HTML can override properties and methods of non-DOM nodes.
No further details were provided.
The vendor credits moz_bug_r_a4 with reporting this vulnerability.
|
Impact:
A remote user can execute arbitrary scripting code with elevated privileges.
|
Solution:
Netscape has issued a fixed version (8.0.1), available at:
http://browser.netscape.com/ns8/download/default.jsp
|
Vendor URL: browser.netscape.com/ns8/product/default.jsp (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 20 May 2005 22:47:42 -0400
Subject: [none]
|
> The Netscape Browser, v8.0.1 includes all Firefox security patches up to 1.0.4.
>
> Fixed in Netscape Browser 8.0.1
>
> • MFSA 2005-44 Privilege escalation via non-DOM property overrides
> • MFSA 2005-43 "Wrapped" javascript: urls bypass security checks
> • MFSA 2005-42 Code execution via javascript: IconURL
|
|