CVE-2012-1956
published 2012-08-29CVE-2012-1956: Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.89%
77.2th percentile
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Affected
264 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 14.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird regressions
vendor_ubuntu·2012-09-28·CVSS 4.3
[MEDIUM] Thunderbird regressions
Title: Thunderbird regressions
Summary: USN-1551-1 introduced regressions in Thunderbird.
USN-1551-1 fixed vulnerabilities in Thunderbird. The new package caused a
regression in the message editor and certain performance regressions as
well. This update fixes the problems.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discove
Ubuntu
Firefox regression
vendor_ubuntu·2012-09-11·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-1548-1 introduced a regression in Firefox.
USN-1548-1 fixed vulnerabilities in Firefox. The new package caused a
regression in Private Browsing which could leak sites visited to the
browser cache. This update fixes the problem.
Original advisory details:
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-08-30·CVSS 4.3
CVE-2012-1970 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Multiple security issues were fixed in Thunderbird.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Thunderbird. If the user
were tricked into opening a specially crafted E-Mail, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted E-Mail, an attacker
could exploit these to cause a denial of service via application crash, or
potential
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-08-29·CVSS 4.3
CVE-2012-1970 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple security issues were fixed in Firefox.
Gary Kwong, Christian Holler, Jesse Ruderman, Steve Fink, Bob Clary, Andrew
Sutherland, Jason Smith, John Schoenick, Vladimir Vukicevic and Daniel
Holbert discovered memory safety issues affecting Firefox. If the user were
tricked into opening a specially crafted page, an attacker could exploit
these to cause a denial of service via application crash, or potentially
execute code with the privileges of the user invoking Firefox.
(CVE-2012-1970, CVE-2012-1971)
Abhishek Arya discovered multiple use-after-free vulnerabilities. If the
user were tricked into opening a specially crafted page, an attacker could
exploit these to cause a denial of service via application crash, or
potentially execute code with
Red Hat
Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
vendor_redhat·2012-08-28·CVSS 4.3
CVE-2012-1956 [MEDIUM] Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
GHSA
GHSA-8449-cw6v-fqcw: Mozilla Firefox before 15
ghsa_unreviewed·2022-05-17
CVE-2012-1956 [MEDIUM] CWE-79 GHSA-8449-cw6v-fqcw: Mozilla Firefox before 15
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
No detection rules found.
No public exploits indexed.
Bugzilla
window.document needs to be [Unforgeable]
bugzilla·2013-07-03·CVSS 4.3
CVE-2012-1956 [MEDIUM] window.document needs to be [Unforgeable]
window.document needs to be [Unforgeable]
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.116 Safari/537.36
Steps to reproduce:
Is this yet another variant of bug 756719 - (CVE-2012-1956)?
Although window.location is marked as non-configurable/non-writable in Firefox 22,
the global window object itself is configurable.
So, non-configurable window.* objects can be shadowed by Object.defineProperty, amplifying XSS attacks and enabling origin-spoofing.
POC: The following works in FF 22
Object.defineProperty(this,"window",{value:{location:{href:"http://xxx.com"}}})
alert(window.location.href);
Similar attacks as bug 756719 apply: fooling plugins/loaded scripts into thinking they are on the wrong origin; we found this
Bugzilla
CVE-2012-1956 Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
bugzilla·2012-08-27·CVSS 4.3
CVE-2012-1956 [MEDIUM] CVE-2012-1956 Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
CVE-2012-1956 Mozilla: Location object can be shadowed using Object.defineProperty (MFSA 2012-59)
Security researcher Mariusz Mlynski reported that it is possible to shadow the location object using Object.defineProperty. This could be used to confuse the current location to plugins, allowing for possible cross-site scripting (XSS) attacks.
External Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-59.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Security researcher Mariusz Mlynski as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:1351 https://rhn.redhat.com/errata/RHSA-2012-1351.html
http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1351.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-59.htmlhttp://www.securityfocus.com/bid/55260http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2https://bugzilla.mozilla.org/show_bug.cgi?id=756719https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16367http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1351.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-59.htmlhttp://www.securityfocus.com/bid/55260http://www.ubuntu.com/usn/USN-1548-1http://www.ubuntu.com/usn/USN-1548-2https://bugzilla.mozilla.org/show_bug.cgi?id=756719https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16367
2012-08-29
Published