Firefox < 9.0 Multiple Vulnerabilities

high Nessus Plugin ID 57351

Synopsis

The remote Windows host contains a web browser that is potentially affected by several vulnerabilities.

Description

The installed version of Firefox is earlier than 9.0 and thus, is potentially affected by the following security issues :

- An out-of-bounds memory access error exists in the 'SVG' implementation and can be triggered when 'SVG' elements are removed during a 'DOMAttrModified' event handler. (CVE-2011-3658)

- Various memory safety errors exist that can lead to memory corruption and possible code execution. (CVE-2011-3660)

- An error exists in the 'YARR' regular expression library that can cause application crashes when handling certain JavaScript statements. (CVE-2011-3661)

- It is possible to detect keystrokes using 'SVG' animation 'accesskey' events even when JavaScript is disabled. (CVE-2011-3663)

- It is possible to crash the application when 'OGG' 'video' elements are scaled to extreme sizes. (CVE-2011-3665)

- A use-after-free error exists related to the function 'nsHTMLSelectElement' that can allow arbitrary code execution during operations such as removal of a parent node of an element. (CVE-2011-3671)

Solution

Upgrade to Firefox 9 or later.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-12-056/

http://www.zerodayinitiative.com/advisories/ZDI-12-128/

http://www.securityfocus.com/archive/1/523754/30/0/threaded

https://www.mozilla.org/en-US/security/advisories/mfsa2011-53/

https://www.mozilla.org/en-US/security/advisories/mfsa2011-54/

https://www.mozilla.org/en-US/security/advisories/mfsa2011-55/

https://www.mozilla.org/en-US/security/advisories/mfsa2011-56/

https://www.mozilla.org/en-US/security/advisories/mfsa2011-58/

https://www.mozilla.org/en-US/security/advisories/mfsa2012-41/

https://bugzilla.mozilla.org/show_bug.cgi?id=739343

Plugin Details

Severity: High

ID: 57351

File Name: mozilla_firefox_90.nasl

Version: 1.25

Type: local

Agent: windows

Family: Windows

Published: 12/20/2011

Updated: 11/15/2018

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.5

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Required KB Items: Mozilla/Firefox/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/20/2011

Vulnerability Publication Date: 12/20/2011

Exploitable With

CANVAS (CANVAS)

Metasploit (Firefox nsSVGValue Out-of-Bounds Access Vulnerability)

Reference Information

CVE: CVE-2011-3658, CVE-2011-3660, CVE-2011-3661, CVE-2011-3663, CVE-2011-3665, CVE-2011-3671

BID: 51133, 51134, 51135, 51136, 51138, 54080