CVE-2011-3079
published 2012-05-01CVE-2011-3079: The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not…
PriorityP429critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.44%
70.6th percentile
The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | firefox-esr | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | thunderbird | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| chrome | <= 18.0.1025.166 | — | |
| mozilla | firefox | < 60.5.0 | 60.5.0 |
| mozilla | firefox | < 65.0 | 65.0 |
| mozilla | firefox | <= 31.6 | — |
| mozilla | firefox | <= 37.0.2 | — |
| mozilla | firefox | >= unspecified < 65 | 65 |
| mozilla | firefox_esr | >= unspecified < 60.5 | 60.5 |
| mozilla | seamonkey | <= 2.33.0 | — |
| mozilla | thunderbird | < 60.5.0 | 60.5.0 |
| mozilla | thunderbird | <= 31.6 | — |
| mozilla | thunderbird | <= 38.0 | — |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= unspecified < 60.5 | 60.5 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-493h-4p68-8587: The Inter-process Communication (IPC) implementation in Google Chrome before 18
ghsa_unreviewed·2022-05-14
CVE-2011-3079 [HIGH] GHSA-493h-4p68-8587: The Inter-process Communication (IPC) implementation in Google Chrome before 18
The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
GHSA
GHSA-5g4g-56fq-mvwf: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and
ghsa_unreviewed·2022-05-13·CVSS 10.0
CVE-2018-18505 [CRITICAL] CWE-287 GHSA-5g4g-56fq-mvwf: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
OSV
CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and
osv·2019-02-05·CVSS 10.0
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Red Hat
Mozilla: Privilege escalation through IPC channel messages
vendor_redhat·2019-01-29·CVSS 10.0
CVE-2018-18505 [CRITICAL] CWE-287 Mozilla: Privilege escalation through IPC channel messages
Mozilla: Privilege escalation through IPC channel messages
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-18505: firefox - An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-...
vendor_debian·2018·CVSS 10.0
CVE-2018-18505 [CRITICAL] CVE-2018-18505: firefox - An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-...
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Scope: local
sid: resolved (fixed in 65.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
bugzilla·2019-01-29·CVSS 10.0
CVE-2018-18505 [CRITICAL] CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18505
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Jed Davis
---
This issue has been addressed in the following products:
Re
Bugzilla
IPC channels created via Endpoint passing don't authenticate the client
bugzilla·2018-10-10·CVSS 10.0
CVE-2011-3079 [CRITICAL] IPC channels created via Endpoint passing don't authenticate the client
IPC channels created via Endpoint passing don't authenticate the client
On Windows we implement IPC channels using named pipes: the server (parent) side creates a pipe and then the client (child) side connects to it by name.
Bug 1087565 / CVE-2011-3079 dealt with the possibility of a sandboxed process connecting to a channel meant for another process and impersonating it to achieve privilege escalation, by adding a 32-bit shared secret that the client must send to the server. (According to comments in the upstream patch, the pipe namespace can be enumerated even by low-privileged processes.)
However, this works correctly only for the initial channel created when the process is started; additional channels created by passing Endpoint instances over IPC don't do this.
The Endpoint-bound
Bugzilla
IPC Channel does not validate the listener.
bugzilla·2014-10-22·CVSS 10.0
CVE-2011-3079 [CRITICAL] IPC Channel does not validate the listener.
IPC Channel does not validate the listener.
We have have probably inherited CVE-2011-3079 from our import of Chromium's IPC code 5½ years ago.
My understanding of this bug is: Chromium IPC endpoints have names, and knowing the name is sufficient to connect to it. These names were predictable and, on Windows, are reflected in the named pipe namespace which an untrusted process can traverse. The patch adds 32 bits of randomness to each name, and excludes that part from the pipe name on Windows. (Anyone with more knowledge of IPC is invited to correct this summary if needed.)
There's also a patch on the bug which seems to not be directly related to the IPC issue itself, and has something to do with Windows security levels: https://crbug.com/117627#c18
+++ This bug was initially created as
http://code.google.com/p/chromium/issues/detail?id=117627http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00036.htmlhttp://osvdb.org/81645http://rhn.redhat.com/errata/RHSA-2015-1012.htmlhttp://secunia.com/advisories/48992http://www.debian.org/security/2015/dsa-3260http://www.mozilla.org/security/announce/2015/mfsa2015-57.htmlhttp://www.securityfocus.com/bid/53309http://www.securitytracker.com/id?1027001https://bugzilla.mozilla.org/show_bug.cgi?id=1087565https://exchange.xforce.ibmcloud.com/vulnerabilities/75271https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14964https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7http://code.google.com/p/chromium/issues/detail?id=117627http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00036.htmlhttp://osvdb.org/81645http://rhn.redhat.com/errata/RHSA-2015-1012.htmlhttp://secunia.com/advisories/48992http://www.debian.org/security/2015/dsa-3260http://www.mozilla.org/security/announce/2015/mfsa2015-57.htmlhttp://www.securityfocus.com/bid/53309http://www.securitytracker.com/id?1027001https://bugzilla.mozilla.org/show_bug.cgi?id=1087565https://exchange.xforce.ibmcloud.com/vulnerabilities/75271https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14964https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7
2012-05-01
Published