CVE-2015-0823
published 2015-02-25CVE-2015-0823: Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.89%
89.1th percentile
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
Affected
222 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 35.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2015-03-09·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-2505-1 introduced a regression in Firefox.
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provi
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restri
Red Hat
Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
vendor_redhat·2015-02-24·CVSS 7.5
CVE-2015-0823 [HIGH] CWE-416 Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package:
GHSA
GHSA-45cf-8gr9-j528: Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36
ghsa_unreviewed·2022-05-14
CVE-2015-0823 [HIGH] GHSA-45cf-8gr9-j528: Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
OSV
firefox regression
osv·2015-03-09·CVSS 4.3
[MEDIUM] firefox regression
firefox regression
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that ope
OSV
firefox vulnerabilities
osv·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could pote
OSV
CVE-2015-0823: Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36
osv·2015-02-25·CVSS 7.5
CVE-2015-0823 [HIGH] CVE-2015-0823: Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0823 Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
bugzilla·2015-02-24·CVSS 7.5
CVE-2015-0823 [HIGH] CVE-2015-0823 Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
CVE-2015-0823 Mozilla: Use-after-free in Developer Console date with OpenType Sanitiser (MFSA 2015-23)
Using the Address Sanitizer tool, security researcher Atte Kettunen found a problem with OpenType Sanitiser (OTS) that resulted in a use-after-free while expanding macros in some circumstances. This use-after-free was only used for information displayed in the developer console and was not exploitable.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-23
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Atte Kettunen as the original reporter.
Statement:
This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-23.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72754http://www.securitytracker.com/id/1031791http://www.ubuntu.com/usn/USN-2505-1https://bugzilla.mozilla.org/show_bug.cgi?id=1098497https://github.com/khaledhosny/ots/commit/003c62d28ae438aa8943cb31535563397f838a2chttps://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-23.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72754http://www.securitytracker.com/id/1031791http://www.ubuntu.com/usn/USN-2505-1https://bugzilla.mozilla.org/show_bug.cgi?id=1098497https://github.com/khaledhosny/ots/commit/003c62d28ae438aa8943cb31535563397f838a2chttps://security.gentoo.org/glsa/201504-01
2015-02-25
Published