Debian DSA-1704-1 : xulrunner - several vulnerabilities

critical Nessus Plugin ID 35378
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote Debian host is missing a security-related update.

Description

Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2008-5500 Jesse Ruderman discovered that the layout engine is vulnerable to DoS attacks that might trigger memory corruption and an integer overflow. (MFSA 2008-60)

- CVE-2008-5503 Boris Zbarsky discovered that an information disclosure attack could be performed via XBL bindings. (MFSA 2008-61)

- CVE-2008-5506 Marius Schilder discovered that it is possible to obtain sensible data via a XMLHttpRequest. (MFSA 2008-64)

- CVE-2008-5507 Chris Evans discovered that it is possible to obtain sensible data via a JavaScript URL. (MFSA 2008-65)

- CVE-2008-5508 Chip Salzenberg discovered possible phishing attacks via URLs with leading whitespaces or control characters.
(MFSA 2008-66)

- CVE-2008-5511 It was discovered that it is possible to perform cross-site scripting attacks via an XBL binding to an 'unloaded document.' (MFSA 2008-68)

- CVE-2008-5512 It was discovered that it is possible to run arbitrary JavaScript with chrome privileges via unknown vectors.
(MFSA 2008-68)

Solution

Upgrade the xulrunner packages.

For the stable distribution (etch) these problems have been fixed in version 1.8.0.15~pre080614i-0etch1.

See Also

https://security-tracker.debian.org/tracker/CVE-2008-5500

https://security-tracker.debian.org/tracker/CVE-2008-5503

https://security-tracker.debian.org/tracker/CVE-2008-5506

https://security-tracker.debian.org/tracker/CVE-2008-5507

https://security-tracker.debian.org/tracker/CVE-2008-5508

https://security-tracker.debian.org/tracker/CVE-2008-5511

https://security-tracker.debian.org/tracker/CVE-2008-5512

https://www.debian.org/security/2009/dsa-1704

Plugin Details

Severity: Critical

ID: 35378

File Name: debian_DSA-1704.nasl

Version: 1.15

Type: local

Agent: unix

Published: 1/15/2009

Updated: 1/4/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:xulrunner, cpe:/o:debian:debian_linux:4.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2009

Reference Information

CVE: CVE-2008-5500, CVE-2008-5503, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5511, CVE-2008-5512

BID: 32925

DSA: 1704

CWE: 20, 79, 200, 264, 399