漏洞信息详情
Mozilla多个产品E4X文档 XML注入攻击漏洞
- CNNVD编号:CNNVD-200811-207
- 危害等级: 中危
- CVE编号: CVE-2008-5024
- 漏洞类型: 代码注入
- 发布时间: 2008-11-13
- 威胁类型: 远程
- 更新时间: 2009-04-16
- 厂 商: mozilla
- 漏洞来源: Chris Evans、Collin...
漏洞简介
Mozilla多个产品的E4X文档存在XML注入攻击漏洞。Mozilla Firefox、Thunderbird以及SeaMonkey没有正确的逸出用于XML处理的引号字符,这使得远程攻击者可以借助一个E4X文档中默认的命名空间,来执行XML注入攻击。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
MandrakeSoft Linux Mandrake 2009.0
Mandriva mozilla-thunderbird-i586.rpm
http://www.mandriva.com/en/download/
Mozilla Firefox 2.0 .1-2.0.17
http://www.mozilla.com/en-US/Firefox/all.HTML
MandrakeSoft Corporate Server 3.0
http://www.mandriva.com/en/download/
Mozilla Firefox 3.0.1
http://www.mozilla.com/en-US/Firefox/all.HTML
Mozilla Firefox 3.0.2
http://www.mozilla.com/en-US/Firefox/all.HTML
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu Firefox-dbg_2.0.0.18+nobinonly-0ubuntu0.7.10_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/f/Firefox/Firefox-dbg_2.0.0.18+nobinonly-0ubuntu0.7.10_powerpc.deb
Mozilla Firefox 2.0.0.13
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/Firefox/all.HTML
Mozilla Firefox 2.0 RC2
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/Firefox/all.HTML
Debian Linux 4.0 amd64
Debian Firefox-dom-inspector_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-dom-i nspector_2.0.0.18-0etch1_all.deb
Debian Linux 4.0 ia-32
Debian Firefox-dom-inspector_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-dom-i nspector_2.0.0.18-0etch1_all.deb
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu abrowser-3.0-branding_3.0.4+nobinonly-0ubuntu0.8.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/f/Firefox-3.0/abrowser-3.0-branding_ 3.0.4+nobinonly-0ubuntu0.8.10.1_sparc.deb
MandrakeSoft Linux Mandrake 2009.0 x86_64
http://www.mandriva.com/en/download/
Mozilla Firefox 2.0.0.15
Mozilla Mozilla Firefox Download
http://www.mozilla.com/en-US/Firefox/all.HTML
Debian Linux 4.0 mips
Debian Firefox-dom-inspector_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-dom-i nspector_2.0.0.18-0etch1_all.deb
Debian Firefox-gnome-support_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-gnome -support_2.0.0.18-0etch1_all.deb
MandrakeSoft Linux Mandrake 2008.1 x86_64
Mandriva mozilla-thunderbird-x86_64.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 arm
Debian Firefox-dom-inspector_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-dom-i nspector_2.0.0.18-0etch1_all.deb
Debian Firefox-gnome-support_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-gnome -support_2.0.0.18-0etch1_all.deb
MandrakeSoft Linux Mandrake 2008.1
Mandriva mozilla-thunderbird-i586.rpm
http://www.mandriva.com/en/download/
Debian Linux 4.0 powerpc
Debian Firefox-dom-inspector_2.0.0.18-0etch1_all.deb
http://security.debian.org/pool/updates/main/i/iceweasel/Firefox-dom-i nspector_2.0.0.18-0etch1_all.deb
参考网址
来源: US-CERT : TA08-319A
名称: TA08-319A
链接:http://www.us-cert.gov/cas/techalerts/TA08-319A.HTML
来源: FEDORA
名称: FEDORA-2008-9669
链接:https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.HTML
来源: MISC
链接:https://bugzilla.mozilla.org/show_bug.cgi?id=453915
来源: VUPEN
名称: ADV-2009-0977
链接:http://www.vupen.com/english/advisories/2009/0977
来源: SECTRACK
名称: 1021192
链接:http://www.securitytracker.com/id?1021192
来源: BID
名称: 32281
链接:http://www.securityfocus.com/bid/32281
来源: REDHAT
名称: RHSA-2008:0978
链接:http://www.redhat.com/support/errata/RHSA-2008-0978.HTML
来源: REDHAT
名称: RHSA-2008:0977
链接:http://www.redhat.com/support/errata/RHSA-2008-0977.HTML
来源:www.mozilla.org
链接:http://www.mozilla.org/security/announce/2008/mfsa2008-58.HTML
来源: MANDRIVA
名称: MDVSA-2008:235
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:235
来源: MANDRIVA
名称: MDVSA-2008:228
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:228
来源: VUPEN
名称: ADV-2008-3146
链接:http://www.frsirt.com/english/advisories/2008/3146
来源: DEBIAN
名称: DSA-1697
链接:http://www.debian.org/security/2009/dsa-1697
来源: DEBIAN
名称: DSA-1696
链接:http://www.debian.org/security/2009/dsa-1696
来源: DEBIAN
名称: DSA-1671
链接:http://www.debian.org/security/2008/dsa-1671
来源: DEBIAN
名称: DSA-1669
链接:http://www.debian.org/security/2008/dsa-1669
来源: SUNALERT
名称: 256408
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
来源: SECUNIA
名称: 34501
链接:http://secunia.com/advisories/34501
来源: SECUNIA
名称: 33434
链接:http://secunia.com/advisories/33434
来源: SECUNIA
名称: 33433
链接:http://secunia.com/advisories/33433
来源: SECUNIA
名称: 32845
链接:http://secunia.com/advisories/32845
来源: SECUNIA
名称: 32721
链接:http://secunia.com/advisories/32721
来源: SECUNIA
名称: 32715
链接:http://secunia.com/advisories/32715
来源: SECUNIA
名称: 32714
链接:http://secunia.com/advisories/32714
来源: SECUNIA
名称: 32695
链接:http://secunia.com/advisories/32695
来源: SECUNIA
名称: 32694
链接:http://secunia.com/advisories/32694
来源: SECUNIA
名称: 32693
链接:http://secunia.com/advisories/32693
来源: SUSE
名称: SUSE-SA:2008:055
链接:http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.HTML
受影响实体
- Mozilla Firefox:1.5.5
- Mozilla Firefox:1.5.7
- Mozilla Firefox:1.5.6
- Mozilla Firefox:1.8
- Mozilla Firefox:1.5.8
补丁
暂无
评论