CVE-2008-2801

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.html
http://rhn.redhat.com/errata/RHSA-2008-0616.html
http://secunia.com/advisories/30878
http://secunia.com/advisories/30898
http://secunia.com/advisories/30903
http://secunia.com/advisories/30911 Vendor Advisory
http://secunia.com/advisories/30949
http://secunia.com/advisories/31005
http://secunia.com/advisories/31008
http://secunia.com/advisories/31021
http://secunia.com/advisories/31023
http://secunia.com/advisories/31069
http://secunia.com/advisories/31076
http://secunia.com/advisories/31183
http://secunia.com/advisories/31195
http://secunia.com/advisories/31377
http://secunia.com/advisories/33433
http://secunia.com/advisories/34501
http://security.gentoo.org/glsa/glsa-200808-03.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
http://wiki.rpath.com/Advisories:rPSA-2008-0216
http://www.debian.org/security/2008/dsa-1607
http://www.debian.org/security/2008/dsa-1615
http://www.debian.org/security/2009/dsa-1697
http://www.mandriva.com/security/advisories?name=MDVSA-2008:136
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15
http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
http://www.redhat.com/support/errata/RHSA-2008-0547.html
http://www.redhat.com/support/errata/RHSA-2008-0549.html
http://www.redhat.com/support/errata/RHSA-2008-0569.html
http://www.securityfocus.com/archive/1/494080/100/0/threaded
http://www.securityfocus.com/bid/30038
http://www.securitytracker.com/id?1020419
http://www.ubuntu.com/usn/usn-619-1
http://www.vupen.com/english/advisories/2008/1993/references
http://www.vupen.com/english/advisories/2009/0977
https://bugzilla.mozilla.org/show_bug.cgi?id=418996
https://bugzilla.mozilla.org/show_bug.cgi?id=424188
https://bugzilla.mozilla.org/show_bug.cgi?id=424426
https://issues.rpath.com/browse/RPL-2646
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.html
http://rhn.redhat.com/errata/RHSA-2008-0616.html
http://secunia.com/advisories/30878
http://secunia.com/advisories/30898
http://secunia.com/advisories/30903
http://secunia.com/advisories/30911 Vendor Advisory
http://secunia.com/advisories/30949
http://secunia.com/advisories/31005
http://secunia.com/advisories/31008
http://secunia.com/advisories/31021
http://secunia.com/advisories/31023
http://secunia.com/advisories/31069
http://secunia.com/advisories/31076
http://secunia.com/advisories/31183
http://secunia.com/advisories/31195
http://secunia.com/advisories/31377
http://secunia.com/advisories/33433
http://secunia.com/advisories/34501
http://security.gentoo.org/glsa/glsa-200808-03.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
http://wiki.rpath.com/Advisories:rPSA-2008-0216
http://www.debian.org/security/2008/dsa-1607
http://www.debian.org/security/2008/dsa-1615
http://www.debian.org/security/2009/dsa-1697
http://www.mandriva.com/security/advisories?name=MDVSA-2008:136
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15
http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
http://www.redhat.com/support/errata/RHSA-2008-0547.html
http://www.redhat.com/support/errata/RHSA-2008-0549.html
http://www.redhat.com/support/errata/RHSA-2008-0569.html
http://www.securityfocus.com/archive/1/494080/100/0/threaded
http://www.securityfocus.com/bid/30038
http://www.securitytracker.com/id?1020419
http://www.ubuntu.com/usn/usn-619-1
http://www.vupen.com/english/advisories/2008/1993/references
http://www.vupen.com/english/advisories/2009/0977
https://bugzilla.mozilla.org/show_bug.cgi?id=418996
https://bugzilla.mozilla.org/show_bug.cgi?id=424188
https://bugzilla.mozilla.org/show_bug.cgi?id=424426
https://issues.rpath.com/browse/RPL-2646
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:47

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.html -
References () http://rhn.redhat.com/errata/RHSA-2008-0616.html - () http://rhn.redhat.com/errata/RHSA-2008-0616.html -
References () http://secunia.com/advisories/30878 - () http://secunia.com/advisories/30878 -
References () http://secunia.com/advisories/30898 - () http://secunia.com/advisories/30898 -
References () http://secunia.com/advisories/30903 - () http://secunia.com/advisories/30903 -
References () http://secunia.com/advisories/30911 - Vendor Advisory () http://secunia.com/advisories/30911 - Vendor Advisory
References () http://secunia.com/advisories/30949 - () http://secunia.com/advisories/30949 -
References () http://secunia.com/advisories/31005 - () http://secunia.com/advisories/31005 -
References () http://secunia.com/advisories/31008 - () http://secunia.com/advisories/31008 -
References () http://secunia.com/advisories/31021 - () http://secunia.com/advisories/31021 -
References () http://secunia.com/advisories/31023 - () http://secunia.com/advisories/31023 -
References () http://secunia.com/advisories/31069 - () http://secunia.com/advisories/31069 -
References () http://secunia.com/advisories/31076 - () http://secunia.com/advisories/31076 -
References () http://secunia.com/advisories/31183 - () http://secunia.com/advisories/31183 -
References () http://secunia.com/advisories/31195 - () http://secunia.com/advisories/31195 -
References () http://secunia.com/advisories/31377 - () http://secunia.com/advisories/31377 -
References () http://secunia.com/advisories/33433 - () http://secunia.com/advisories/33433 -
References () http://secunia.com/advisories/34501 - () http://secunia.com/advisories/34501 -
References () http://security.gentoo.org/glsa/glsa-200808-03.xml - () http://security.gentoo.org/glsa/glsa-200808-03.xml -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152 -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 -
References () http://wiki.rpath.com/Advisories:rPSA-2008-0216 - () http://wiki.rpath.com/Advisories:rPSA-2008-0216 -
References () http://www.debian.org/security/2008/dsa-1607 - () http://www.debian.org/security/2008/dsa-1607 -
References () http://www.debian.org/security/2008/dsa-1615 - () http://www.debian.org/security/2008/dsa-1615 -
References () http://www.debian.org/security/2009/dsa-1697 - () http://www.debian.org/security/2009/dsa-1697 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:136 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:136 -
References () http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15 - () http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15 -
References () http://www.mozilla.org/security/announce/2008/mfsa2008-23.html - () http://www.mozilla.org/security/announce/2008/mfsa2008-23.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0547.html - () http://www.redhat.com/support/errata/RHSA-2008-0547.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0549.html - () http://www.redhat.com/support/errata/RHSA-2008-0549.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0569.html - () http://www.redhat.com/support/errata/RHSA-2008-0569.html -
References () http://www.securityfocus.com/archive/1/494080/100/0/threaded - () http://www.securityfocus.com/archive/1/494080/100/0/threaded -
References () http://www.securityfocus.com/bid/30038 - () http://www.securityfocus.com/bid/30038 -
References () http://www.securitytracker.com/id?1020419 - () http://www.securitytracker.com/id?1020419 -
References () http://www.ubuntu.com/usn/usn-619-1 - () http://www.ubuntu.com/usn/usn-619-1 -
References () http://www.vupen.com/english/advisories/2008/1993/references - () http://www.vupen.com/english/advisories/2008/1993/references -
References () http://www.vupen.com/english/advisories/2009/0977 - () http://www.vupen.com/english/advisories/2009/0977 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=418996 - () https://bugzilla.mozilla.org/show_bug.cgi?id=418996 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=424188 - () https://bugzilla.mozilla.org/show_bug.cgi?id=424188 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=424426 - () https://bugzilla.mozilla.org/show_bug.cgi?id=424426 -
References () https://issues.rpath.com/browse/RPL-2646 - () https://issues.rpath.com/browse/RPL-2646 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.html - () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.html - () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html - () https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html -

Information

Published : 2008-07-07 23:41

Updated : 2024-11-21 00:47


NVD link : CVE-2008-2801

Mitre link : CVE-2008-2801

CVE.ORG link : CVE-2008-2801


JSON object : View

Products Affected

mozilla

  • firefox
  • seamonkey
CWE
CWE-287

Improper Authentication