CVE-2012-1944
published 2012-06-05CVE-2012-1944: The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.85%
76.7th percentile
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.
Affected
106 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.9 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-06-27·CVSS 10.0
CVE-2011-3101 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
USN-1463-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this
Ubuntu
Firefox regressions
vendor_ubuntu·2012-06-20·CVSS 10.0
[CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-1463-1 introduced regressions in Firefox.
USN-1463-1 fixed vulnerabilities in Firefox. The new package caused a
regression in the rendering of Hebrew text and the ability of the Hotmail
inbox to auto-update. This update fixes the problem.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL impleme
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-06-06·CVSS 10.0
CVE-2012-1937 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this issue has not been
disclosed at this time. (CVE-2011-3101)
Adam Barth discovered that certain inline event handlers were not being
blocked prop
Red Hat
Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
vendor_redhat·2012-06-05·CVSS 4.3
CVE-2012-1944 [MEDIUM] Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.
GHSA
GHSA-mpv9-qhv2-p7fj: The Content Security Policy (CSP) implementation in Mozilla Firefox 4
ghsa_unreviewed·2022-05-14
CVE-2012-1944 [MEDIUM] CWE-79 GHSA-mpv9-qhv2-p7fj: The Content Security Policy (CSP) implementation in Mozilla Firefox 4
The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not block inline event handlers, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
bugzilla·2012-06-03·CVSS 4.3
CVE-2012-1944 [MEDIUM] CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
Security researcher Adam Barth found that inline event handlers, such as onclick, were no longer blocked by Content Security Policy's (CSP) inline-script blocking feature. Web applications relying on this feature of CSP to protect against cross-site scripting (XSS) were not fully protected.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-36.html
http://www.w3.org/TR/CSP/
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges security researcher Adam Barth as the original
reporter.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0710 htt
Bugzilla
<img onerror="..."> execute even when inline scripts are blocked by CSP
bugzilla·2012-05-02
[MEDIUM] <img onerror="..."> execute even when inline scripts are blocked by CSP
execute even when inline scripts are blocked by CSP
See http://dvcs.w3.org/hg/webappsec/file/tip/tests/csp/submitted/webkit/CSP_default-src-inline-allowed.php
I also reported this in person at the W3C WebAppSec working group face-to-face.
Discussion:
Created attachment 620531
PoC from linked checkin (PHP)
Please attach any proof of concepts when opening a bug since external resources may disappear.
---
sg:high ?
---
Yes, I think so.
---
Note that the current CSP tests for inline script only try body onload=...some script... which apparently is blocked.
---
I think this was regressed by http://hg.mozilla.org/mozilla-central/diff/9e6aa5ee6425/content/events/src/nsEventListenerManager.cpp#l1.24. By not setting 'doc' we never descend into the block that checks the CSP.
---
Also
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0710.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0715.htmlhttp://secunia.com/advisories/49981http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-36.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=751422https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17005http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0710.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0715.htmlhttp://secunia.com/advisories/49981http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-36.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=751422https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17005
2012-06-05
Published