CVE-2013-5598
published 2013-10-30CVE-2013-5598: PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote…
PriorityP341high8.3CVSS 2.0
AVNACMAuNCCIPAP
EPSS
2.94%
85.7th percentile
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 24.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:C/I:P/A:P
vendor_redhat8.3HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-10-29·CVSS 5.0
CVE-2013-1739 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,
CVE-2013-5592)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. An attacker could potentially exploit this to conduct
URL spoofing or clickjacking attacks (CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. An attacker could potenti
Red Hat
Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
vendor_redhat·2013-10-29·CVSS 8.3
CVE-2013-5598 [HIGH] Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-qc4r-65pv-9r8p: PDF
ghsa_unreviewed·2022-05-17
CVE-2013-5598 [HIGH] GHSA-qc4r-65pv-9r8p: PDF
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
No detection rules found.
No public exploits indexed.
Bugzilla
pdfjs privilege escalation round 2
bugzilla·2014-05-24
[MEDIUM] pdfjs privilege escalation round 2
pdfjs privilege escalation round 2
Created attachment 8428290
pdfPluginRound2-testcase-new.html
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:29.0) Gecko/20100101 Firefox/29.0 (Beta/Release)
Build ID: 20140506152807
Steps to reproduce:
I created an embed object to load the pdfjs implementation as a plugin and then used setTimeout(pseudo race condition) to load a privileged xul document.
Actual results:
Even though the window isn't actually visible a chrome URI xul document is loaded and can be accessed as a sub-frame of the content window by doing window[0].
Expected results:
I should have received an exception since once again this is loading data of a type that is not expected. I think this one slipped through the cracks before because I used an iframe to do this. This time it
Bugzilla
CVE-2013-5598 Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
bugzilla·2013-10-28·CVSS 8.3
CVE-2013-5598 [HIGH] CVE-2013-5598 Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
CVE-2013-5598 Mozilla: Security bypass of PDF.js checks using iframes (MFSA 2013-99)
Security researcher Cody Crews discovered a method to append an iframe into an embedded PDF object rendered with the chrome privileged PDF.js. This can used to bypass security restrictions to load local or chrome privileged files and objects within the embedded PDF object. This can lead to information disclosure of local system files.
In general this flaw cannot be exploited through email in the Thunderbird and Seamonkey products because scripting is disabled, but is potentially a risk in browser or browser-like contexts.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-99.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upst
Bugzilla
pdf.js iframe injection allows sites to load local files or even chrome privileged pages into an iframe
bugzilla·2013-09-25
[MEDIUM] pdf.js iframe injection allows sites to load local files or even chrome privileged pages into an iframe
pdf.js iframe injection allows sites to load local files or even chrome privileged pages into an iframe
Created attachment 809860
mapLocalFiles.html
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Firefox/23.0 (Beta/Release)
Build ID: 20130814063812
Steps to reproduce:
I created and added an embed element to the document of a page initially setting the src attribute for the embed to 'data:application/pdf,'. This triggers the pdfjs implementation and begins to load it to preview the plugin. Immediately after I created an iframe element and appended it as a child of the embed element. Normally when previewing a pdf as a plugin, an anonymous iframe is created as a child of the embed element, but apparently any iframe that is a child of the embed element will behave
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-99.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=920515https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19133https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-99.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=920515https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19133https://security.gentoo.org/glsa/201504-01
2013-10-30
Published