packetstorm_rss ([info]packetstorm_rss) rakstīja,
@ 2013-12-23 15:30:00

Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Firefox 15.0.1 Code Execution
On versions of Firefox from 5.0 to 15.0.1, the InstallTrigger global, when given invalid input, would throw an exception that did not have an __exposedProps__ property set. By re-setting this property on the exception object's prototype, the chrome-based defineProperty method is made available. With the defineProperty method, functions belonging to window and document can be overriden with a function that gets called from chrome-privileged context. From here, another vulnerability in the crypto.generateCRMFRequest function is used to "peek" into the context's private scope. Since the window does not have a chrome:// URL, the insecure parts of Components.classes are not available, so instead the AddonManager API is invoked to silently install a malicious plugin.


Neesi iežurnalējies. Iežurnalēties?