CVE-2007-5947
published 2007-11-14CVE-2007-5947: The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.71%
84.3th percentile
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.9 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.1.6 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjp2-qv3r-5pqp: The jar protocol handler in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-6589 [MEDIUM] CWE-79 GHSA-mjp2-qv3r-5pqp: The jar protocol handler in Mozilla Firefox before 2
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.
GHSA
GHSA-2cph-6c7j-7mmc: The jar protocol handler in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2007-5947 [MEDIUM] CWE-79 GHSA-2cph-6c7j-7mmc: The jar protocol handler in Mozilla Firefox before 2
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
Ubuntu
Firefox regression
vendor_ubuntu·2007-12-04·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: Firefox regression
USN-546-1 fixed vulnerabilities in Firefox. The upstream update included
a faulty patch which caused the drawImage method of the canvas element to
fail. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Firefox incorrectly associated redirected sites
as the origin of "jar:" contents. A malicious web site could exploit this
to modify or steal confidential data (such as passwords) from other web
sites. (CVE-2007-5947)
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5959)
Gregory Fleischer discovered that it was poss
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-11-26·CVSS 4.3
CVE-2007-5959 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
It was discovered that Firefox incorrectly associated redirected sites
as the origin of "jar:" contents. A malicious web site could exploit this
to modify or steal confidential data (such as passwords) from other web
sites. (CVE-2007-5947)
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5959)
Gregory Fleischer discovered that it was possible to use JavaScript to
manipulate Firefox's Referer header. A malicious web site could exploit
this to conduct cross-site request forgeries against sites that relied
only on Referer headers for protection from such attacks. (CVE-2007-596
Red Hat
jar: protocol XSS
vendor_redhat·2007-02-08·CVSS 4.3
CVE-2007-5947 [MEDIUM] CWE-79 jar: protocol XSS
jar: protocol XSS
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
No detection rules found.
No public exploits indexed.
http://browser.netscape.com/releasenotes/http://bugs.gentoo.org/show_bug.cgi?id=198965http://bugs.gentoo.org/show_bug.cgi?id=200909http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00004.htmlhttp://secunia.com/advisories/27605http://secunia.com/advisories/27793http://secunia.com/advisories/27796http://secunia.com/advisories/27797http://secunia.com/advisories/27800http://secunia.com/advisories/27816http://secunia.com/advisories/27838http://secunia.com/advisories/27845http://secunia.com/advisories/27855http://secunia.com/advisories/27944http://secunia.com/advisories/27955http://secunia.com/advisories/27957http://secunia.com/advisories/27979http://secunia.com/advisories/28001http://secunia.com/advisories/28016http://secunia.com/advisories/28171http://secunia.com/advisories/28277http://secunia.com/advisories/28398http://secunia.com/advisories/29164http://security.gentoo.org/glsa/glsa-200712-21.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.365006http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374833http://sunsolve.sun.com/search/document.do?assetkey=1-26-231441-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018977.1-1http://wiki.rpath.com/Advisories:rPSA-2008-0093http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0260http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093http://www.debian.org/security/2007/dsa-1424http://www.debian.org/security/2007/dsa-1425http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issueshttp://www.kb.cert.org/vuls/id/715737http://www.mandriva.com/security/advisories?name=MDKSA-2007:246http://www.mozilla.org/security/announce/2007/mfsa2007-37.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1082.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1083.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1084.htmlhttp://www.securityfocus.com/archive/1/488002/100/0/threadedhttp://www.securityfocus.com/archive/1/488971/100/0/threadedhttp://www.securityfocus.com/bid/26385http://www.securitytracker.com/id?1018928http://www.ubuntu.com/usn/usn-546-2http://www.vupen.com/english/advisories/2007/3818http://www.vupen.com/english/advisories/2007/4002http://www.vupen.com/english/advisories/2007/4018http://www.vupen.com/english/advisories/2008/0083http://www.vupen.com/english/advisories/2008/0643https://bugzilla.mozilla.org/show_bug.cgi?id=369814https://exchange.xforce.ibmcloud.com/vulnerabilities/38356https://issues.rpath.com/browse/RPL-1984https://issues.rpath.com/browse/RPL-1995https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9873https://usn.ubuntu.com/546-1/https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00115.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00135.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00168.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg01011.htmlhttp://browser.netscape.com/releasenotes/http://bugs.gentoo.org/show_bug.cgi?id=198965http://bugs.gentoo.org/show_bug.cgi?id=200909http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00004.htmlhttp://secunia.com/advisories/27605http://secunia.com/advisories/27793http://secunia.com/advisories/27796http://secunia.com/advisories/27797http://secunia.com/advisories/27800http://secunia.com/advisories/27816http://secunia.com/advisories/27838http://secunia.com/advisories/27845http://secunia.com/advisories/27855http://secunia.com/advisories/27944http://secunia.com/advisories/27955http://secunia.com/advisories/27957http://secunia.com/advisories/27979http://secunia.com/advisories/28001http://secunia.com/advisories/28016http://secunia.com/advisories/28171http://secunia.com/advisories/28277http://secunia.com/advisories/28398http://secunia.com/advisories/29164http://security.gentoo.org/glsa/glsa-200712-21.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.365006http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374833http://sunsolve.sun.com/search/document.do?assetkey=1-26-231441-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018977.1-1http://wiki.rpath.com/Advisories:rPSA-2008-0093http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0260http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093http://www.debian.org/security/2007/dsa-1424http://www.debian.org/security/2007/dsa-1425http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issueshttp://www.kb.cert.org/vuls/id/715737http://www.mandriva.com/security/advisories?name=MDKSA-2007:246http://www.mozilla.org/security/announce/2007/mfsa2007-37.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1082.html
+ 22 more references
2007-11-14
Published