Mozilla Firefox URLBar Null Byte File Remote Code Execution Vulnerability
Publish Date: 15 Februar 2011
Schweregrad:: Mittel
Hinweisdatum: 15 Februar 2011
Beschreibung
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
Trend Micro Lösungen
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
Lösungen
Trend Micro Deep Security DPI Rule Number: 1001051
Trend Micro Deep Security DPI Rule Name: 1001051 - Mozilla Firefox URLBar Null Byte File Remote Code Execution Vulnerability
Betroffene Software und Version:
- Mozilla Firefox 0.10
- Mozilla Firefox 0.10.1
- Mozilla Firefox 0.8
- Mozilla Firefox 0.9
- Mozilla Firefox 0.9.1
- Mozilla Firefox 0.9.2
- Mozilla Firefox 0.9.3
- Mozilla Firefox 1.0
- Mozilla Firefox 1.0.1
- Mozilla Firefox 1.0.2
- Mozilla Firefox 1.0.3
- Mozilla Firefox 1.0.4
- Mozilla Firefox 1.0.5
- Mozilla Firefox 1.0.6
- Mozilla Firefox 1.0.7
- Mozilla Firefox 1.0.8
- Mozilla Firefox 1.5
- Mozilla Firefox 1.5.0.1
- Mozilla Firefox 1.5.0.10
- Mozilla Firefox 1.5.0.11
- Mozilla Firefox 1.5.0.2
- Mozilla Firefox 1.5.0.3
- Mozilla Firefox 1.5.0.4
- Mozilla Firefox 1.5.0.5
- Mozilla Firefox 1.5.0.6
- Mozilla Firefox 1.5.0.7
- Mozilla Firefox 1.5.0.8
- Mozilla Firefox 1.5.0.9
- Mozilla Firefox 1.5.1
- Mozilla Firefox 1.5.2
- Mozilla Firefox 1.5.3
- Mozilla Firefox 1.5.4
- Mozilla Firefox 1.5.5
- Mozilla Firefox 1.5.6
- Mozilla Firefox 1.5.7
- Mozilla Firefox 1.5.8
- Mozilla Firefox 2.0
- Mozilla Firefox 2.0 RC2
- Mozilla Firefox 2.0 RC3
- Mozilla Firefox 2.0 beta 1
- Mozilla Firefox 2.0.0.1
- Mozilla Firefox 2.0.0.2
- Mozilla Firefox 2.0.0.3
- Mozilla Firefox 2.0.0.4