Bug 2169667 (CVE-2007-3845) - CVE-2007-3845 Mozilla: Unescaped URIs passed to external programs
Summary: CVE-2007-3845 Mozilla: Unescaped URIs passed to external programs
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2007-3845
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-02-14 09:18 UTC by Mauro Matteo Cascella
Modified: 2023-02-16 00:41 UTC (History)
5 users (show)

Fixed In Version: firefox 2.0.0.6, thunderbird 1.5.0.13, thunderbird 2.0.0.6
Doc Type: ---
Doc Text:
The Mozilla Foundation Security Advisory describes this flaw as: Jesper Johansson pointed out that Mozilla did not percent-encode spaces and double-quotes in URIs handed off to external programs for handling, which can cause the receiving program to mistakenly interpret a single URI as multiple arguments. The danger depends on the arguments supported by the specific receiving program, though at the very least we know Firefox (and Thunderbird) 2.0.0.4 and older could be used to run arbitrary script (see MFSA 2007-23). The vast majority of programs do not have dangerous arguments, though many could still be made to do something unexpected.
Clone Of:
Environment:
Last Closed: 2023-02-16 00:41:34 UTC
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2023-02-14 09:18:55 UTC
Jesper Johansson pointed out that Mozilla did not percent-encode spaces and double-quotes in URIs handed off to external programs for handling, which can cause the receiving program to mistakenly interpret a single URI as multiple arguments. The danger depends on the arguments supported by the specific receiving program, though at the very least we know Firefox (and Thunderbird) 2.0.0.4 and older could be used to run arbitrary script (see MFSA 2007-23). The vast majority of programs do not have dangerous arguments, though many could still be made to do something unexpected.

References:
https://www.mozilla.org/en-US/security/advisories/mfsa2007-27/
https://nvd.nist.gov/vuln/detail/CVE-2007-3845
https://bugzilla.mozilla.org/show_bug.cgi?id=389106
https://bugzilla.mozilla.org/show_bug.cgi?id=389580

Comment 1 Product Security DevOps Team 2023-02-16 00:41:32 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2007-3845


Note You need to log in before you can comment on or make changes to this bug.