Информационная безопасность
[RU] switch to English

Дополнительная информация

  Многочисленные уязвимости безопасности в Mozilla Firefox / Seamonkey

  US-CERT Technical Cyber Security Alert TA08-087A -- Mozilla Updates for Multiple Vulnerabilities

  Mozilla Foundation Security Advisory 2008-19

  Mozilla Foundation Security Advisory 2008-18

  Mozilla Foundation Security Advisory 2008-17

Date:26 марта 2008 г.
Subject:Mozilla Foundation Security Advisory 2008-13

Mozilla Foundation Security Advisory 2008-13

Title: Multiple XSS vulnerabilities from character encoding
Impact: Moderate
Announced: March 25, 2008
Reporter: Alexey Proskuryakov, Yosuke Hasegawa, Simon Montagu
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox
 SeaMonkey 1.1.8

WebKit developer Alexey Proskuryakov reported that the Mozilla HTML parser treated the backspace character as whitespace contrary to the HTML specification and different from other browsers. This difference might lead to Cross-site Scripting (XSS) risks on sites which filtered input in accordance with the specification.

Yosuke Hasegawa reported a flaw in the way Mozilla parses the control character 0x80 under Shift_JIS encoding. This flaw could potentially be used to evade web-site input filters and result in a XSS attack hazard. While investigating, Mozilla developer Simon Montagu discovered several variants of this flaw involving zero-length non-ASCII sequences in ISO-2022-JP, ISO-2022-CN, ISO-2022-KR, and HZ-GB-2312.

These flaws were fixed in and prior to Firefox but the announcement was held until other browser vendors could fix related flaws.

Disable JavaScript until a version containing these fixes can be installed. Although the flaw is in the parser, the main risk is using these flaws to construct a XSS attack which requires scripting to be enabled.

   * Character encoding XSS bugs
   * CVE-2008-0416

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород