[Japanese]

JVNDB-2007-000134

Sage vulnerable to arbitrary script execution

Overview

Sage is an RSS and Atom feed reader extension for Mozilla Firefox. If a malicious script is embedded in an RSS feed, Sage does not properly handle the data, which may allow an arbitrary script to be executed on a user's web browser.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 6.4 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


Sage
  • Sage 1.3.9 and earlier
  • Sage++

Impact

An arbitrary script may be executed on Mozilla Firefox. For example, local files could be accessed.
Solution

This vulnerability affects Sage++ as well.

As of February 9, 2007, Sage++ is no longer available and is no longer being updated. It is recommended that Sage++ users use the latest version of Sage.
Vendor Information

Sage
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [NVD Evaluation]
CVE (What is CVE?)

  1. CVE-2007-0896
References

  1. JVN : JVN#84430861
  2. National Vulnerability Database (NVD) : CVE-2007-0896
  3. Secunia Advisory : SA24086
  4. SecurityFocus : 22493
  5. ISS X-Force Database : 32395
  6. SecurityTracker : 1017624
Revision History

  • [2008/05/21]
      Web page published