Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Mozilla Browsers CSS moz-binding Cross Domain Scripting

Subscribe

Check Point Reference: CPAI-2006-182
Date Published:
Severity:
Last Updated:
Source: SecurityFocus Bugtraq ID: 16427
Industry Reference(s): CVE-2006-0496
Protection Provided by: Security Gateway
  • R75
Who is Vulnerable?
Mozilla Foundation Firefox 1.5.0.1 and prior
Mozilla Foundation Mozilla Suite 1.7.12 and prior
Vulnerability Description
The Mozilla based web browsers are full featured web browsers which serve as popular alternatives to the Microsoft Internet Explorer. The browsers are capable of interpreting HTML, JavaScript, CSS, as well as a myriad of other popular Internet standard formats. The Mozilla based browsers are capable of interpreting the Extensible Binding Language (XBL).
Vulnerability Details
There exists a Cross Site Scripting vulnerability in Mozilla web browser and its derivatives. The flaw is caused by a validation error when processing malicious CSS or HTML documents containing a specially crafted "-moz-binding" property. A remote attacker may exploit this issue to execute arbitrary scripting code in the target's browser session in the context of an arbitrary site.
A successful attack leveraging this vulnerability may result in HTTP cookies being stolen from the target user and arbitrary code being executed by the target's browser in the security context of an arbitrary domain. The target host will not exhibit any abnormal or suspicious behaviour during an attack.

Protection Overview
This protection will detect and block attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R75

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > IPS Software Blade > Web Intelligence > HTTP Client Protections > Mozilla Firefox Vulnerabilities.
2. In the right pane, double-click the Mozilla Browsers CSS moz-binding Cross Domain Scripting protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Mozilla browsers CSS moz-binding cross domain scripting