exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mozilla Firefox JavaScript Issues

Mozilla Firefox JavaScript Issues
Posted Dec 7, 2009
Authored by Topsec

Mozilla Firefox suffers from spoofing and race conditions in relation to JavaScript functionality.

tags | advisory, spoof, javascript
advisories | CVE-2009-4129, CVE-2009-4130
SHA-256 | b2090c9012cb9380aa027790f71166c32e3b35dd2ca90482e19470b4408381a4

Mozilla Firefox JavaScript Issues

Change Mirror Download
There exist two seperate security issues in Mozilla Firefox concerning 
JavaScript prompts appearing from domain which is not the true origin.
The first is about spawning JavaScript prompted message over web page of
another domain, so in effect, the address bar and the browser content
are from one domain, but the prompted JavaScript message is generated by
script from another different domain. This is resulted from a race
condition scenario, in which the browser is first navigated to URL of
another domain, then before it's loaded, immediately launch JavaScript
message prompting, so JavaScript message is displayed over a web page
other than its origin web page. The issue here only affects Firefox, and
doesn't seem to affect Internet Explorer and Google Chrome. This is
CVE-2009-4129. The second is regarding the function named
"MakeScriptDialogTitle"(in file "nsGlobalWindow.cpp" of Firefox source
code), responsible for "Script Dialog Title", which is designed to show
"host". The "MakeScriptDialogTitle" function removes usernames and
passwords from URL, with a purpose of "spoof prevention", but it's not
enough, because script dialog has limited and predictable width, so only
the prefix will be displayed if domain name is long. This is
CVE-2009-4130. Topsec has the credit.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close