Bug 476280 (CVE-2008-5507) - CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message
Summary: CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2008-5507
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-12-12 20:50 UTC by Josh Bressers
Modified: 2019-09-29 12:28 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-12-25 17:00:02 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2008:1036 0 normal SHIPPED_LIVE Critical: firefox security update 2008-12-17 01:32:17 UTC
Red Hat Product Errata RHSA-2008:1037 0 normal SHIPPED_LIVE Critical: seamonkey security update 2008-12-17 01:31:59 UTC
Red Hat Product Errata RHSA-2009:0002 0 normal SHIPPED_LIVE Moderate: thunderbird security update 2009-01-07 10:28:27 UTC

Description Josh Bressers 2008-12-12 20:50:52 UTC
Security researcher Chris Evans reported that a website coud access data
from a different domain by loading JavaScript which redirects to an
off-domain resource containing data which is not parsable as JavaScript.
Upon attempting to load the data as JavaScript, an error message is
generated and the data comprising the invalid JavaScript is then accessible
by the loading page via the window.onerror DOM API. This issue could be
used by a malicious website to steal private data from users who are
authenticated on the redirected website.

Comment 2 Josh Bressers 2008-12-16 23:17:37 UTC
This is now public:
http://www.mozilla.org/security/announce/2008/mfsa2008-65.html

Comment 3 Tomas Hoger 2008-12-18 09:17:25 UTC
Further details and PoC in Chris Evans' advisory:
  http://scary.beasts.org/security/CESA-2008-011.html

Comment 4 Fedora Update System 2008-12-21 08:24:57 UTC
seamonkey-1.1.14-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2008-12-21 08:29:07 UTC
xulrunner-1.9.0.5-1.fc10, firefox-3.0.5-1.fc10, epiphany-2.24.1-3.fc10, epiphany-extensions-2.24.0-3.fc10, blam-1.8.5-5.fc10, devhelp-0.22-2.fc10, evolution-rss-0.1.2-3.fc10, galeon-2.0.7-4.fc10, gecko-sharp2-0.13-3.fc10, gnome-python2-extras-2.19.1-25.fc10, gnome-web-photo-0.3-13.fc10, google-gadgets-0.10.3-2.fc10, kazehakase-0.5.6-1.fc10.2, Miro-1.2.7-3.fc10, mozvoikko-0.9.5-5.fc10, mugshot-1.2.2-4.fc10, pcmanx-gtk2-0.3.8-4.fc10, ruby-gnome2-0.18.1-2.fc10, yelp-2.24.0-4.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2008-12-21 08:35:54 UTC
xulrunner-1.9.0.5-1.fc9, firefox-3.0.5-1.fc9, epiphany-2.22.2-6.fc9, epiphany-extensions-2.22.1-6.fc9, blam-1.8.5-4.fc9.1, cairo-dock-1.6.3.1-1.fc9.2, chmsee-1.0.1-7.fc9, devhelp-0.19.1-7.fc9, evolution-rss-0.1.0-5.fc9, galeon-2.0.7-4.fc9, gnome-python2-extras-2.19.1-22.fc9, gnome-web-photo-0.3-16.fc9, google-gadgets-0.10.3-2.fc9, gtkmozembedmm-1.4.2.cvs20060817-24.fc9, kazehakase-0.5.6-1.fc9.2, Miro-1.2.7-3.fc9, mozvoikko-0.9.5-5.fc9, mugshot-1.2.2-4.fc9, ruby-gnome2-0.17.0-4.fc9, totem-2.23.2-9.fc9, yelp-2.22.1-7.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2008-12-21 08:40:04 UTC
seamonkey-1.1.14-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2008-12-21 08:42:32 UTC
firefox-2.0.0.19-1.fc8, epiphany-2.20.3-9.fc8, epiphany-extensions-2.20.1-12.fc8, blam-1.8.3-20.fc8, cairo-dock-1.6.3.1-1.fc8.2, chmsee-1.0.0-6.31.fc8, devhelp-0.16.1-12.fc8, evolution-rss-0.0.8-14.fc8, galeon-2.0.4-7.fc8.3, gnome-python2-extras-2.19.1-20.fc8, gnome-web-photo-0.3-15.fc8, kazehakase-0.5.6-1.fc8.2, liferea-1.4.15-6.fc8, Miro-1.2.7-3.fc8, openvrml-0.17.10-3.0.fc8, ruby-gnome2-0.17.0-4.fc8, yelp-2.20.0-15.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2008-12-21 08:44:15 UTC
seamonkey-1.1.14-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Vincent Danen 2010-12-25 17:00:02 UTC
This was addressed via:

Red Hat Enterprise Linux version 4 (firefox) RHSA-2008:1036
Red Hat Enterprise Linux version 5 (firefox) RHSA-2008:1036
Red Hat Enterprise Linux version 2.1 (seamonkey) RHSA-2008:1037
Red Hat Enterprise Linux version 3 (seamonkey) RHSA-2008:1037
Red Hat Enterprise Linux version 4 (seamonkey) RHSA-2008:1037
Red Hat Enterprise Linux version 4 (thunderbird) RHSA-2009:0002
Red Hat Enterprise Linux Desktop version 5 (thunderbird) RHSA-2009:0002
RHEL Optional Productivity Applications version 5 (thunderbird)	RHSA-2009:0002


Note You need to log in before you can comment on or make changes to this bug.