ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Actively exploited Firefox, Tor Browser 0-day patched, update now!

criticalVulnerability exploited in the wildimportance 60CVE-2016-9079

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-9079
Use-After-Free in Mozilla Firefox and Tor Browser SVG Animation Exploited in the Wild

CVE-2016-9079 is a use-after-free flaw (CWE-416) in the SVG Animation component of Mozilla's Gecko engine, affecting Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1, as well as the Firefox-ESR-based Tor Browser and distro-packaged builds on Debian and Red Hat Enterprise Linux. It is triggered when the browser renders SVG content with animations, typically by loading a crafted web page, causing a freed SVG animation object to be reused and corrupting memory. A successful attack can lead to arbitrary code execution in the browser context or disclosure of sensitive memory contents; the assigned CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network-triggered memory corruption with high confidentiality impact and no privileges required. The in-the-wild exploit observed at disclosure targeted Firefox and Tor Browser users on Windows. The flaw has public PoC exploits, carries an EPSS 30-day exploitation probability of 87.4% (100th percentile), and was added to the CISA KEV catalog on 2023-06-22 with a required action to apply vendor updates.

Do: Upgrade Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later, and install the corresponding patched Tor Browser build; users on Windows were the observed in-the-wild targets, so prioritize those hosts. On Debian and Red Hat Enterprise Linux, apply the vendor's updated firefox/thunderbird/tor packages per their advisories, consistent with the CISA KEV required action. As an interim mitigation, restrict loading of untrusted web content with animated SVG and verify no machines in the environment are still running Firefox versions older than 50.0.2.

7.587% KEV PoC ×3
  • mozilla Firefox < 50.0.2
  • mozilla Firefox ESR < 45.5.1
  • mozilla Thunderbird < 45.5.1
  • +3 more
mass~200-300 million Firefox users/install base at the time of disclosure (late 2016), plus roughly 1-2 million Tor Browser daily users (Windows-targeted…
Full article275 words · extracted from helpnetsecurity.com · click to collapse

Mozilla and the Tor Project have released security updates that fix the Firefox 0-day flaw that was spotted being exploited to de-anonymize Tor Browser users.

Tor Browser 0-day

It is still unknown who started wielding the exploit initially, although it’s similarity to a previous one used by the FBI in 2013 to target users of hidden services seems to point in that direction.

The vulnerability (CVE-2016-9079) affects SVG Animation module in Firefox and in Tor Browser, since the latter is based on the former (specifically, on the Firefox ESR browser).

The use-after-free, remote code execution flaw is likely being exploited to reveal information about the machine (MAC address), and through it the identity of its user. But, according to GData Software researchers, no persistent threat is left on the target computer, as everything is done in memory.

Firefox users should upgrade to version 50.0.2, Firefox ESR users to version 45.5.1, and Thunderbird users to version 45.5.1, as soon as possible. The exploit code has been made public, and cyber criminals are likely to start using it soon – if they aren’t already.

Tor Browser users should upgrade to version 6.0.7.

“The security flaw responsible for this urgent release is already actively exploited on Windows systems. Even though there is currently, to the best of our knowledge, no similar exploit for OS X or Linux users available the underlying bug affects those platforms as well,” Tor Browser developer Georg Koppen explained, and added that “Tor Browser users who had set their security slider to ‘High’ are believed to have been safe from this vulnerability.”

This vulnerability can also be mitigated by disabling JavaScript on each of these browsers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2016/12/01/firefox-tor-browser-0-day-patched/