CVE-2006-1729
published 2006-04-14CVE-2006-1729: Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.23%
80.6th percentile
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | firefox | < firefox 1.5.dfsg+1.5.0.4-1 (sid) | firefox 1.5.dfsg+1.5.0.4-1 (sid) |
| debian | firefox | < firefox 1.5.dfsg+1.5.0.2-1 (sid) | firefox 1.5.dfsg+1.5.0.2-1 (sid) |
| mozilla | firefox | <= 1.5.0.3 | — |
| mozilla | firefox | >= 1.0 < 1.0.8 | 1.0.8 |
| mozilla | firefox | >= 1.5 < 1.5.0.2 | 1.5.0.2 |
| mozilla | mozilla_suite | < 1.7.13 | 1.7.13 |
| mozilla | seamonkey | < 1.0.1 | 1.0.1 |
| mozilla | seamonkey | <= 1.0.1 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2gxf-f3cr-5m3p: Mozilla Firefox 1
ghsa_unreviewed·2022-05-03
CVE-2006-1729 [MEDIUM] CWE-20 GHSA-2gxf-f3cr-5m3p: Mozilla Firefox 1
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
GHSA
GHSA-q2jj-w55g-3m5j: Firefox 1
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2006-2782 [MEDIUM] CWE-20 GHSA-q2jj-w55g-3m5j: Firefox 1
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Ubuntu
mozilla vulnerabilities
vendor_ubuntu·2006-07-26·CVSS 4.3
CVE-2006-2775 [MEDIUM] mozilla vulnerabilities
Title: mozilla vulnerabilities
Summary: mozilla vulnerabilities
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web script
with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar
attack was discovered by moz_bug_r_a4 that leveraged SelectionObject
notifications that were called in privileged context. (MFSA 2006-43,
CVE-2006-2777)
Mikolaj Habryn discovered a buffer overflow in the crypto.signText()
f
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2006-07-25·CVSS 4.3
CVE-2006-2775 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06
LTS release. This update provides the corresponding fixes for Ubuntu
5.04 and Ubuntu 5.10.
For reference, these are the details of the original USN:
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web script
with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar
at
Ubuntu
firefox vulnerabilities
vendor_ubuntu·2006-06-09·CVSS 7.5
CVE-2006-2775 [HIGH] firefox vulnerabilities
Title: firefox vulnerabilities
Summary: firefox vulnerabilities
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web script
with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar
attack was discovered by moz_bug_r_a4 that leveraged SelectionObject
notifications that were called in privileged context. (MFSA 2006-43,
CVE-2006-2777)
Mikolaj Habryn discovered a buffer overflow in the crypto.signText()
f
Red Hat
security flaw
vendor_redhat·2006-06-01·CVSS 4.3
CVE-2006-2782 [MEDIUM] security flaw
security flaw
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Ubuntu
Mozilla vulnerabilities
vendor_ubuntu·2006-04-28·CVSS 5.0
CVE-2006-1736 [MEDIUM] Mozilla vulnerabilities
Title: Mozilla vulnerabilities
Summary: Mozilla vulnerabilities
Web pages with extremely long titles caused subsequent launches of
Mozilla browser to hang for up to a few minutes, or caused Mozilla to
crash on computers with insufficient memory. (CVE-2005-4134)
Igor Bukanov discovered that the JavaScript engine did not properly
declare some temporary variables. Under some rare circumstances, a
malicious website could exploit this to execute arbitrary code with
the privileges of the user. (CVE-2006-0292, CVE-2006-1742)
The function XULDocument.persist() did not sufficiently validate the
names of attributes. An attacker could exploit this to inject
arbitrary XML code into the file 'localstore.rdf', which is read and
evaluated at startup. This could include JavaScript commands that
would
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2006-04-20·CVSS 5.0
CVE-2005-4134 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Web pages with extremely long titles caused subsequent launches of
Firefox browser to hang for up to a few minutes, or caused Firefox to
crash on computers with insufficient memory. (CVE-2005-4134)
Igor Bukanov discovered that the JavaScript engine did not properly
declare some temporary variables. Under some rare circumstances, a
malicious website could exploit this to execute arbitrary code with
the privileges of the user. (CVE-2006-0292, CVE-2006-1742)
The function XULDocument.persist() did not sufficiently validate the
names of attributes. An attacker could exploit this to inject
arbitrary XML code into the file 'localstore.rdf', which is read and
evaluated at startup. This could include JavaScript commands that
would
Red Hat
security flaw
vendor_redhat·2006-04-14·CVSS 4.3
CVE-2006-1729 [MEDIUM] security flaw
security flaw
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
Debian
CVE-2006-2782: firefox - Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which...
vendor_debian·2006·CVSS 4.3
CVE-2006-2782 [MEDIUM] CVE-2006-2782: firefox - Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which...
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
Debian
CVE-2006-1729: firefox - Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before ...
vendor_debian·2006·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729: firefox - Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before ...
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2782 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-2782 [MEDIUM] CVE-2006-2782 security flaw
CVE-2006-2782 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Bugzilla
CVE-2006-1729 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729 security flaw
CVE-2006-1729 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
Bugzilla
multiple critical Firefox, Mozilla vulnerabilities (CVE-2006-0749, CVE-2006-1724, et al.)
bugzilla·2006-04-17·CVSS 9.3
CVE-2006-0749 [CRITICAL] multiple critical Firefox, Mozilla vulnerabilities (CVE-2006-0749, CVE-2006-1724, et al.)
multiple critical Firefox, Mozilla vulnerabilities (CVE-2006-0749, CVE-2006-1724, et al.)
Red Hat has issued RHSA:2006-0328-01 for Firefox
releasing firefox-1.0.8-1.4.1.
"Critical: Firefox security update
...
"Updated firefox packages that fix several security bugs are now available.
"This update has been rated as having critical security impact by the Red
Hat Security Response Team. ...
"Several bugs were found in the way Firefox processes malformed javascript.
A malicious web page could modify the content of a different open web page,
possibly stealing sensitive information or conducting a cross-site
scripting attack. (CVE-2006-1731, CVE-2006-1732, CVE-2006-1741)
"Several bugs were found in the way Firefox processes certain javascript
actions. A malicious web page could execute ar
Bugzilla
CVE-2006-1729 File stealing by changing input type
bugzilla·2006-04-13·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729 File stealing by changing input type
CVE-2006-1729 File stealing by changing input type
File stealing by changing input type
Claus Jørgensen reports that a text input box can be pre-filled with a
filename and then turned into a file-upload control with the contents
intact, allowing a malicious website the ability to steal any local file
whose name they can guess.
Jesse Ruderman reports a variation, changing the type of the input control
in an event handler to work around some of the initial checks.
Workaround
Upgrade to fixed version.
References
[1]https://bugzilla.mozilla.org/show_bug.cgi?id=325947
[2]https://bugzilla.mozilla.org/show_bug.cgi?id=328566
This issue also affects FC4
Discussion:
These issues have been resolved in FEDORA-2006-411 for FC5 and FEDORA-2006-410
for FC4
Bugzilla
CVE-2006-1729 File stealing by changing input type
bugzilla·2006-04-13·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729 File stealing by changing input type
CVE-2006-1729 File stealing by changing input type
File stealing by changing input type
Claus Jørgensen reports that a text input box can be pre-filled with a
filename and then turned into a file-upload control with the contents
intact, allowing a malicious website the ability to steal any local file
whose name they can guess.
Jesse Ruderman reports a variation, changing the type of the input control
in an event handler to work around some of the initial checks.
Workaround
Upgrade to fixed version.
References
[1]https://bugzilla.mozilla.org/show_bug.cgi?id=325947
[2]https://bugzilla.mozilla.org/show_bug.cgi?id=328566
Discussion:
Lifting embargo
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with
Bugzilla
CVE-2006-1729 File stealing by changing input type
bugzilla·2006-04-13·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729 File stealing by changing input type
CVE-2006-1729 File stealing by changing input type
File stealing by changing input type
Claus Jørgensen reports that a text input box can be pre-filled with a
filename and then turned into a file-upload control with the contents
intact, allowing a malicious website the ability to steal any local file
whose name they can guess.
Jesse Ruderman reports a variation, changing the type of the input control
in an event handler to work around some of the initial checks.
Workaround
Upgrade to fixed version.
References
[1]https://bugzilla.mozilla.org/show_bug.cgi?id=325947
[2]https://bugzilla.mozilla.org/show_bug.cgi?id=328566
This issue also affects FC4
Discussion:
Lifting embargo
---
This bug was fixed for FC4 in Fedora Update FEDORA-2006-488
.
This bug was fixed for FC5 in Fedora
Bugzilla
CVE-2006-1729 File stealing by changing input type
bugzilla·2006-04-13·CVSS 4.3
CVE-2006-1729 [MEDIUM] CVE-2006-1729 File stealing by changing input type
CVE-2006-1729 File stealing by changing input type
File stealing by changing input type
Claus Jørgensen reports that a text input box can be pre-filled with a
filename and then turned into a file-upload control with the contents
intact, allowing a malicious website the ability to steal any local file
whose name they can guess.
Jesse Ruderman reports a variation, changing the type of the input control
in an event handler to work around some of the initial checks.
Workaround
Upgrade to fixed version.
References
[1]https://bugzilla.mozilla.org/show_bug.cgi?id=325947
[2]https://bugzilla.mozilla.org/show_bug.cgi?id=328566
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Lifting embargo
---
An advisory has been issued which should help the problem
describe
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txtftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.htmlhttp://secunia.com/advisories/19631http://secunia.com/advisories/19649http://secunia.com/advisories/19696http://secunia.com/advisories/19714http://secunia.com/advisories/19721http://secunia.com/advisories/19729http://secunia.com/advisories/19746http://secunia.com/advisories/19759http://secunia.com/advisories/19794http://secunia.com/advisories/19811http://secunia.com/advisories/19852http://secunia.com/advisories/19862http://secunia.com/advisories/19863http://secunia.com/advisories/19902http://secunia.com/advisories/19941http://secunia.com/advisories/21033http://secunia.com/advisories/21622http://secunia.com/advisories/22066http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1http://support.avaya.com/elmodocs2/security/ASA-2006-205.htmhttp://www.debian.org/security/2006/dsa-1044http://www.debian.org/security/2006/dsa-1046http://www.debian.org/security/2006/dsa-1051http://www.gentoo.org/security/en/glsa/glsa-200604-12.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200604-18.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:075http://www.mandriva.com/security/advisories?name=MDKSA-2006:076http://www.mozilla.org/security/announce/2006/mfsa2006-23.htmlhttp://www.novell.com/linux/security/advisories/2006_35_mozilla.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0328.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0329.htmlhttp://www.securityfocus.com/archive/1/436296/100/0/threadedhttp://www.securityfocus.com/archive/1/436338/100/0/threadedhttp://www.securityfocus.com/archive/1/446658/100/200/threadedhttp://www.securityfocus.com/bid/17516http://www.vupen.com/english/advisories/2006/1356http://www.vupen.com/english/advisories/2006/3391http://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2008/0083https://exchange.xforce.ibmcloud.com/vulnerabilities/25823https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10922https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1929https://usn.ubuntu.com/271-1/https://usn.ubuntu.com/275-1/ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txtftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.htmlhttp://secunia.com/advisories/19631http://secunia.com/advisories/19649http://secunia.com/advisories/19696http://secunia.com/advisories/19714http://secunia.com/advisories/19721http://secunia.com/advisories/19729http://secunia.com/advisories/19746http://secunia.com/advisories/19759http://secunia.com/advisories/19794http://secunia.com/advisories/19811http://secunia.com/advisories/19852http://secunia.com/advisories/19862http://secunia.com/advisories/19863http://secunia.com/advisories/19902http://secunia.com/advisories/19941http://secunia.com/advisories/21033http://secunia.com/advisories/21622http://secunia.com/advisories/22066http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1http://support.avaya.com/elmodocs2/security/ASA-2006-205.htmhttp://www.debian.org/security/2006/dsa-1044http://www.debian.org/security/2006/dsa-1046http://www.debian.org/security/2006/dsa-1051http://www.gentoo.org/security/en/glsa/glsa-200604-12.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200604-18.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:075http://www.mandriva.com/security/advisories?name=MDKSA-2006:076http://www.mozilla.org/security/announce/2006/mfsa2006-23.htmlhttp://www.novell.com/linux/security/advisories/2006_35_mozilla.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0328.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0329.htmlhttp://www.securityfocus.com/archive/1/436296/100/0/threadedhttp://www.securityfocus.com/archive/1/436338/100/0/threadedhttp://www.securityfocus.com/archive/1/446658/100/200/threadedhttp://www.securityfocus.com/bid/17516http://www.vupen.com/english/advisories/2006/1356http://www.vupen.com/english/advisories/2006/3391http://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2008/0083https://exchange.xforce.ibmcloud.com/vulnerabilities/25823https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10922https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1929https://usn.ubuntu.com/271-1/https://usn.ubuntu.com/275-1/
2006-04-14
Published