CVE-2011-3659
published 2012-02-01CVE-2011-3659: Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7…
PriorityP265critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
36.51%
98.3th percentile
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 3.6.26 | 3.6.26 |
| mozilla | firefox | >= 4.0 < 10.0 | 10.0 |
| mozilla | seamonkey | < 2.7 | 2.7 |
| mozilla | thunderbird | < 3.1.18 | 3.1.18 |
| mozilla | thunderbird | >= 5.0 < 10.0 | 10.0 |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Firefox 8/8.0.1 and 9/9.0.1 on Windows XP only; User-Agent strings matching Firefox/8.0 or Firefox/9.0 combined with NT 5.1 should be treated as high-risk in the context of this CVE. ↗
- →Exploit delivers a malicious HTML page with Content-Type text/html; monitor for browser-based exploit delivery serving heap-spray content to Firefox 8/9 clients. ↗
- →ROP chain for Firefox 8 on XP uses gadgets exclusively from MOZCRT19.dll; presence of MOZCRT19.dll ROP gadget addresses (e.g. 0x7818f50b, 0x7819548e) on the stack is a strong indicator of exploitation. ↗
- →ROP chains for Firefox 9 and 9.0.1 on XP use gadgets from nspr4.dll; stack traces containing nspr4.dll ROP gadget addresses (e.g. 0x1000ed58, 0x1000ed4a, 0x10006a01, 0x10006a11) indicate active exploitation. ↗
- →The exploit uses a heap spray with a fixed allocation size of 0x40000 and a return address of 0x0C0C0C0C; detecting 0x0C0C0C0C as an EIP/return value or large repeated heap allocations of 0x40000 bytes in Firefox processes is indicative of exploitation. ↗
- →The Metasploit module is tracked as mozilla_attribchildremoved; IDS/EDR rules should flag this module name in network or process telemetry. ↗
- ·The exploit only supports Windows XP targets (NT 5.1); other OS versions cause the module to return a 404, so detections based on OS fingerprinting should be scoped to XP. ↗
- ·The exploit explicitly checks for Firefox 8.0/8.0.1 and 9.0/9.0.1 User-Agent strings and rejects all other browser versions, limiting the attack surface to those specific versions. ↗
- ·The vulnerability also affects Firefox before 3.6.26, Thunderbird before 3.1.18 and 5.0–9.0, and SeaMonkey before 2.7, but the public Metasploit exploit only targets Firefox 8/9 on Windows XP. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-02-17·CVSS 9.3
CVE-2012-0452 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Thunderbird can crash due to memory corruption.
If the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If the user were tricked into opening a specially crafted
file, an attacker could exploit this to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invokin
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-02-08·CVSS 9.3
CVE-2012-0442 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Jesse Ruderman and Bob Clary discovered memory safety issues affecting
Thunderbird. If the user were tricked into opening a specially crafted
page, an attacker could exploit these to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Thunderbird. (CVE-2012-0442)
It was discovered that Thunderbird did not properly handle node removal in
the DOM. If the user were tricked into opening a specially crafted page, an
attacker could exploit this to cause a denial of service via application
crash, or potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2011-3659)
It was discovered that memory corruption c
Ubuntu
Xulrunnner vulnerabilities
vendor_ubuntu·2012-02-08·CVSS 9.3
CVE-2012-0442 [CRITICAL] Xulrunnner vulnerabilities
Title: Xulrunnner vulnerabilities
Summary: Several security issues were fixed in Xulrunner.
Jesse Ruderman and Bob Clary discovered memory safety issues affecting the
Gecko Browser engine. If the user were tricked into opening a specially
crafted page, an attacker could exploit these to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2012-0442)
It was discovered that the Gecko Browser engine did not properly handle
node removal in the DOM. If the user were tricked into opening a specially
crafted page, an attacker could exploit this to cause a denial of service
via application crash, or potentially execute code with the privileges of
the user invoking Xulrunner. (CVE-2011-3659)
It was discovered that
Ubuntu
Mozvoikko update
vendor_ubuntu·2012-02-03·CVSS 10.0
CVE-2012-0450 [CRITICAL] Mozvoikko update
Title: Mozvoikko update
Summary: This update provides compatible Mozvoikko packages for the latest Firefox.
USN-1355-1 fixed vulnerabilities in Firefox. This update provides an
updated Mozvoikko package for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially e
Ubuntu
ubufox and webfav update
vendor_ubuntu·2012-02-03·CVSS 10.0
[CRITICAL] ubufox and webfav update
Title: ubufox and webfav update
Summary: This update provides compatible ubufox and webfav packages for the latest
Firefox.
USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated
ubufox and webfav packages for use with the latest Firefox.
Original advisory details:
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-02-03·CVSS 10.0
CVE-2012-0450 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
It was discovered that if a user chose to export their Firefox Sync key
the "Firefox Recovery Key.html" file is saved with incorrect permissions,
making the file contents potentially readable by other users.
(CVE-2012-0450)
Nicolas Gregoire and Aki Helin discovered that when processing a malformed
embedded XSLT stylesheet, Firefox can crash due to memory corruption. If
the user were tricked into opening a specially crafted page, an attacker
could exploit this to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2012-0449)
It was discovered that memory corruption could occur during the decoding of
Ogg Vorbis files. If th
Red Hat
Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
vendor_redhat·2012-01-31·CVSS 9.3
CVE-2011-3659 [CRITICAL] Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
Mozilla: child nodes from nsDOMAttribute still accessible after removal of nodes (MFSA 2012-04)
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
GHSA
GHSA-6j4m-9ghg-x3p4: Use-after-free vulnerability in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-13
CVE-2011-3659 [HIGH] CWE-416 GHSA-6j4m-9ghg-x3p4: Use-after-free vulnerability in Mozilla Firefox before 3
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
No detection rules found.
Exploit-DB
Mozilla Firefox 8/9 - 'AttributeChildRemoved()' Use-After-Free (Metasploit)
exploitdb·2012-05-13
CVE-2011-3659 Mozilla Firefox 8/9 - 'AttributeChildRemoved()' Use-After-Free (Metasploit)
Mozilla Firefox 8/9 - 'AttributeChildRemoved()' Use-After-Free (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Firefox 8/9 AttributeChildRemoved() Use-After-Free',
'Description' => %q{
This module exploits a use-after-free vulnerability in Firefox 8/8.0.1 and 9/9.0.1.
Removal of child nodes from the nsDOMAttribute can allow for a child
to still be accessible after removal due to a premature notification
of AttributeChildRemoved. Since mFirstChild is not set to NULL until
after this call is made, this means the removed child wi
Metasploit
Firefox 8/9 AttributeChildRemoved() Use-After-Free
metasploit
Firefox 8/9 AttributeChildRemoved() Use-After-Free
Firefox 8/9 AttributeChildRemoved() Use-After-Free
This module exploits a use-after-free vulnerability in Firefox 8/8.0.1 and 9/9.0.1. Removal of child nodes from the nsDOMAttribute can allow for a child to still be accessible after removal due to a premature notification of AttributeChildRemoved. Since mFirstChild is not set to NULL until after this call is made, this means the removed child will be accessible after it has been removed. By carefully manipulating the memory layout, this can lead to arbitrary code execution.
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:013http://www.mozilla.org/security/announce/2012/mfsa2012-04.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=708198https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14697http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-02/msg00011.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:013http://www.mozilla.org/security/announce/2012/mfsa2012-04.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=708198https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14697
2012-02-01
Published