Mozilla Firefox 基于堆栈的缓冲区溢出漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1193300 漏洞类型 缓冲区溢出
发布时间 2006-10-05 更新时间 2006-10-09
CVE编号 CVE-2006-5159 CNNVD-ID CNNVD-200610-065
漏洞平台 N/A CVSS评分 7.5
|漏洞来源
https://cxsecurity.com/issue/WLB-2006100044
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200610-065
|漏洞详情
MozillaFirefox中存在基于堆栈的缓冲区溢出漏洞,远程攻击者可以通过与JavaScript有关的未明向量执行任意代码。
|漏洞EXP
CNet is writing about some 0day vulnerabilities in Firefox that were 
demonstrated at ToorCon '06 by Mischa Spiegelmock and Andrew Wbeelsoi:

http://news.zdnet.com/2100-1009_22-6121608.html

Mischa and Andrew also claim to have found about 30 0day vulnerabilities 
in Firefox. The article mention that the vulnerabilities from the 
presentation are specific to Firefox's implementation of Javascript and 
hints that they are stack overflows. On the other hand, the recent 
security-related Mozilla commits following the presentation deal with 
improper validation of scope chain lookups in jsxml.c, jsinterp.c and 
jsiter.c, which could allow injecting content into the Chrome context. 
We'll probably see a security release of Firefox in the next week, but 
in the mean time I have put a couple of links to the code diff's that 
fix these vulnerabilities at

http://blogs.securiteam.com/index.php/archives/657

--
Thor Larholm
|参考资料

来源:MISC
链接:http://www.securitypronews.com/insiderreports/insider/spn-49-20061003FirefoxVulnerabilityClaimWasAJoke.html
来源:BID
名称:20294
链接:http://www.securityfocus.com/bid/20294
来源:BID
名称:20282
链接:http://www.securityfocus.com/bid/20282
来源:BUGTRAQ
名称:200610010dayinFirefoxfromToorCon'06
链接:http://www.securityfocus.com/archive/1/archive/1/447497/100/0/threaded
来源:BUGTRAQ
名称:20061001zero-dayflawsinFirefox:about30unpatchedFirefoxflaws
链接:http://www.securityfocus.com/archive/1/archive/1/447493/100/0/threaded
来源:SECTRACK
名称:1016962
链接:http://securitytracker.com/id?1016962
来源:MISC
链接:http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/
来源:XF
名称:firefox-multiple-javascript-bo(29317)
链接:http://xforce.iss.net/xforce/xfdb/29317
来源:SREASON
名称:1678
链接:http://securityreason.com/securityalert/1678