[NEWS] Gecko Table Rebuilding Code Execution
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 27 Apr 2006 15:08:05 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Gecko Table Rebuilding Code Execution
------------------------------------------------------------------------
SUMMARY
RebuildConsideringRows() is a Gecko function that handles table rows.
Improper input validation allow attackers to execute arbitrary code in
Gecko based products.
DETAILS
Vulnerable Systems:
* Firefox version 1.5 and above
* Firefox version 1.5.0.1 and prior
* Firefox version 1.0 and above
* Firefox version 1.0.7 and prior
* Thunderbird version 1.5 and above
* Thunderbird version 1.5.0.1 and prior
* Thunderbird version 1.0 and above
* Thunderbird version 1.0.7 and prior
* SeaMonkey version 1.0
* Mozilla Suite version 1.7 and above
* Mozilla Suite version 1.7.12 and prior
The specific flaw exists within the routine RebuildConsideringRows()
during the rebuilding of nonsensical table tags. When the Mozilla engine
attempts to fix the malformed table, an attacker is capable of triggering
a memory corruption that can lead to code execution from user-supplied
data.
The vulnerability allow attackers to execute arbitrary code on vulnerable
installations of the Mozilla/Firefox web browser and Thunderbird e-mail
client. User interaction is required to exploit this vulnerability in that
the target must visit a malicious page or open a malicious e-mail.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748>
CVE-2006-0748
Disclosure Timeline:
2006.02.28 - Vulnerability reported to vendor
2006.04.25 - Public release of advisory
ADDITIONAL INFORMATION
The information has been provided by <mailto:zdi-disclosures@xxxxxxxx>
zdi-disclosures.
The original article can be found at:
<http://www.zerodayinitiative.com/advisories/ZDI-06-011.html>
http://www.zerodayinitiative.com/advisories/ZDI-06-011.html
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [EXPL] Fenice Buffer Overflow Vulnerability (Long URI, Exploit Code)
- Next by Date: [NEWS] Apple Mac OS X Safari DoS
- Previous by thread: [EXPL] Fenice Buffer Overflow Vulnerability (Long URI, Exploit Code)
- Next by thread: [NEWS] Apple Mac OS X Safari DoS
- Index(es):
Relevant Pages
- [NEWS] Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Mozilla Thunderbird MIME External-Body
Heap Overflow Vulnerability ... Thunderbird could allow an attacker to execute arbitrary
code with the ... (Securiteam) - [NEWS] Quake 3 Infostring DoS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... United Offensive version 1.51
and prior ... void showinfo; ... int main{ ... (Securiteam) - [NEWS] Gecko Based Browsers CSS Letter-Spacing Integer Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Firefox version 1.5.0.1
and prior ... Thunderbird version 1.5 and above ... This vulnerability allows
attackers to execute arbitrary code on ... (Securiteam) - [NEWS] Quake 3 Engine Buffer Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... United Offensive version 1.5.1
and prior ... * Star Wars Jedi Knight II: Jedi Outcast version 1.04 and prior ...
If an attacker joins a server and sends a too big message any client in ... (Securiteam) - [NEWS] eMule / Lmule / xMule Multiple Remote Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... With such a large user base
eMule is not only a ... * eMule version 0.29c and prior ... * xMule version
1.5.6a and prior ... (Securiteam)