Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22958
HistoryDec 17, 2009 - 12:00 a.m.

Mozilla Foundation Security Advisory 2009-71

2009-12-1700:00:00
vulners.com
23

Mozilla Foundation Security Advisory 2009-71

Title: GeckoActiveXObject exception messages can be used to enumerate installed COM objects
Impact: Low
Announced: December 15, 2009
Reporter: Gregory Fleischer
Products: Firefox, SeaMonkey

Fixed in: Firefox 3.5.6
Firefox 3.0.16
SeaMonkey 2.0.1
Description

Security researcher Gregory Fleischer reported that the exception messages generated by Mozilla's GeckoActiveXObject differ based on whether or not the requested COM object's ProgID is present in the system registry. A malicious site could use this vulnerability to enumerate a list of COM objects installed on a user's system and create a profile to track the user across browsing sessions.
References

* https://bugzilla.mozilla.org/show_bug.cgi?id=503451
* CVE-2009-3987