Debian DSA-1707-1 : iceweasel - several vulnerabilities

critical Nessus Plugin ID 35384
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote Debian host is missing a security-related update.

Description

Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2008-5500 Jesse Ruderman discovered that the layout engine is vulnerable to DoS attacks that might trigger memory corruption and an integer overflow. (MFSA 2008-60)

- CVE-2008-5503 Boris Zbarsky discovered that an information disclosure attack could be performed via XBL bindings. (MFSA 2008-61)

- CVE-2008-5504 It was discovered that attackers could run arbitrary JavaScript with chrome privileges via vectors related to the feed preview. (MFSA 2008-62)

- CVE-2008-5506 Marius Schilder discovered that it is possible to obtain sensible data via a XMLHttpRequest. (MFSA 2008-64)

- CVE-2008-5507 Chris Evans discovered that it is possible to obtain sensible data via a JavaScript URL. (MFSA 2008-65)

- CVE-2008-5508 Chip Salzenberg discovered possible phishing attacks via URLs with leading whitespaces or control characters.
(MFSA 2008-66)

- CVE-2008-5510 Kojima Hajime and Jun Muto discovered that escaped null characters were ignored by the CSS parser and could lead to the bypass of protection mechanisms (MFSA 2008-67)

- CVE-2008-5511 It was discovered that it is possible to perform cross-site scripting attacks via an XBL binding to an 'unloaded document.' (MFSA 2008-68)

- CVE-2008-5512 It was discovered that it is possible to run arbitrary JavaScript with chrome privileges via unknown vectors.
(MFSA 2008-68)

- CVE-2008-5513 moz_bug_r_a4 discovered that the session-restore feature does not properly sanitise input leading to arbitrary injections. This issue could be used to perform an XSS attack or run arbitrary JavaScript with chrome privileges. (MFSA 2008-69)

Solution

Upgrade the iceweasel package.

For the stable distribution (etch) these problems have been fixed in version 2.0.0.19-0etch1.

See Also

https://security-tracker.debian.org/tracker/CVE-2008-5500

https://security-tracker.debian.org/tracker/CVE-2008-5503

https://security-tracker.debian.org/tracker/CVE-2008-5504

https://security-tracker.debian.org/tracker/CVE-2008-5506

https://security-tracker.debian.org/tracker/CVE-2008-5507

https://security-tracker.debian.org/tracker/CVE-2008-5508

https://security-tracker.debian.org/tracker/CVE-2008-5510

https://security-tracker.debian.org/tracker/CVE-2008-5511

https://security-tracker.debian.org/tracker/CVE-2008-5512

https://security-tracker.debian.org/tracker/CVE-2008-5513

https://www.debian.org/security/2009/dsa-1707

Plugin Details

Severity: Critical

ID: 35384

File Name: debian_DSA-1707.nasl

Version: 1.15

Type: local

Agent: unix

Published: 1/16/2009

Updated: 1/4/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:iceweasel, cpe:/o:debian:debian_linux:4.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 1/15/2009

Reference Information

CVE: CVE-2008-5500, CVE-2008-5503, CVE-2008-5504, CVE-2008-5506, CVE-2008-5507, CVE-2008-5508, CVE-2008-5510, CVE-2008-5511, CVE-2008-5512, CVE-2008-5513

BID: 32882

DSA: 1707

CWE: 20, 79, 200, 264, 399