This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox v1.0.3 exploit released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2005-05-07
Updated May 8th 2005 00:03 UTC
"…FrSIRT (aka K-OTik) published a 0-day exploit against FireFox 1.0.3 . <_<
Impact: remote code execution without user interaction
Patch: none available
Workaround: disable javascript …"

- http://secunia.com/advisories/15292/
Release Date: 2005-05-08
"NOTE: Exploit code is publicly available.
The vulnerabilities have been confirmed in version 1.0.3. Other versions may also be affected.
Solution:
Disable JavaScript…"

:ph34r:
FYI…

Firefox 1.0.3 Alternate Workaround
- http://isc.sans.org/diary.php?date=2005-05-08
Updated May 9th 2005 06:05 UTC
"…alternate (and perhaps better) workaround for the recently announced remote code execution flaw in Firefox 1.0.3 is to disable “remote software installation,” rather than disabling all Javascript. In the Win32 version of Firefox, this is accomplished by:

Tools | Options | Web Features | and clearing the “Allow web sites to install software" checkbox.

Two Notes:
1) There is some question as to the availability of this setting in Firefox on platforms other than Windows… YMMV.
2) While this seems like a reasonable workaround, it has not been tested…"

:oops:
FYI…

- http://secunia.com/advisories/15292/
Last Update: 2005-05-09
"…NOTE: A temporary solution has been added to the sites "update.mozilla.org" and "addons.mozilla.org" where requests are redirected to "do-not-add.mozilla.org". This will stop the publicly available exploit code using a combination of vulnerability 1 and 2 to execute arbitrary code in the default settings of Firefox."

B)
Per http://secunia.com/advisories/15292/ update 2005-05-11:

- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1476

- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1477

(Both have same references)
"# FULLDISC:20050508 Firefox Remote Compromise Leaked
# URL: http://marc.theaimsgroup.com/?l=full-discl…53138007647&w=2
# FULLDISC: 20050508 Firefox Remote Compromise Technical Details
# URL: http://marc.theaimsgroup.com/?l=full-discl…56301530553&w=2
# MISC: http://greyhatsecurity.org/firefox.htm
# MISC: http://greyhatsecurity.org/vulntests/ffrc.htm
# CONFIRM: http://www.mozilla.org/security/announce/mfsa2005-42.html
# MISC: https://bugzilla.mozilla.org/show_bug.cgi?id=293302
# MISC: https://bugzilla.mozilla.org/show_bug.cgi?id=292691
# FRSIRT: ADV-2005-0493
# URL: http://www.frsirt.com/english/advisories/2005/0493
# SECUNIA:15292
# URL: http://secunia.com/advisories/15292 …"