Debian DSA-1392-1 : xulrunner - several vulnerabilities

high Nessus Plugin ID 27547

Synopsis

The remote Debian host is missing a security-related update.

Description

Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2007-1095 Michal Zalewski discovered that the unload event handler had access to the address of the next page to be loaded, which could allow information disclosure or spoofing.

- CVE-2007-2292 Stefano Di Paola discovered that insufficient validation of user names used in Digest authentication on a website allows HTTP response splitting attacks.

- CVE-2007-3511 It was discovered that insecure focus handling of the file upload control can lead to information disclosure.
This is a variant of CVE-2006-2894.

- CVE-2007-5334 Eli Friedman discovered that web pages written in Xul markup can hide the titlebar of windows, which can lead to spoofing attacks.

- CVE-2007-5337 Georgi Guninski discovered the insecure handling of smb:// and sftp:// URI schemes may lead to information disclosure. This vulnerability is only exploitable if Gnome-VFS support is present on the system.

- CVE-2007-5338 'moz_bug_r_a4' discovered that the protection scheme offered by XPCNativeWrappers could be bypassed, which might allow privilege escalation.

- CVE-2007-5339 L. David Baron, Boris Zbarsky, Georgi Guninski, Paul Nickerson, Olli Pettay, Jesse Ruderman, Vladimir Sukhoy, Daniel Veditz, and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code.

- CVE-2007-5340 Igor Bukanov, Eli Friedman, and Jesse Ruderman discovered crashes in the JavaScript engine, which might allow the execution of arbitrary code.

The oldstable distribution (sarge) doesn't contain xulrunner.

Solution

Upgrade the xulrunner packages.

For the stable distribution (etch) these problems have been fixed in version 1.8.0.14~pre071019b-0etch1. Builds for hppa and mipsel will be provided later.

See Also

https://security-tracker.debian.org/tracker/CVE-2007-1095

https://security-tracker.debian.org/tracker/CVE-2007-2292

https://security-tracker.debian.org/tracker/CVE-2007-3511

https://security-tracker.debian.org/tracker/CVE-2006-2894

https://security-tracker.debian.org/tracker/CVE-2007-5334

https://security-tracker.debian.org/tracker/CVE-2007-5337

https://security-tracker.debian.org/tracker/CVE-2007-5338

https://security-tracker.debian.org/tracker/CVE-2007-5339

https://security-tracker.debian.org/tracker/CVE-2007-5340

https://www.debian.org/security/2007/dsa-1392

Plugin Details

Severity: High

ID: 27547

File Name: debian_DSA-1392.nasl

Version: 1.18

Type: local

Agent: unix

Published: 10/25/2007

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:xulrunner, cpe:/o:debian:debian_linux:4.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 10/20/2007

Reference Information

CVE: CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340

CWE: 16, 20, 200

DSA: 1392