Sploitus

Exploit for Firefox crypto.generateCRMFRequest command execution

saint · 2014-08-21

Exploit Code

MARKDOWN33 lines
## https://sploitus.com/exploit?id=SAINT:417B7745BC680DB5735ED5B5A6B1B30F
Added: 08/21/2014  
CVE: [CVE-2013-1710](<https://vulners.com/cve/CVE-2013-1710>)  
BID: [61900](<http://www.securityfocus.com/bid/61900>)  
OSVDB: [96019](<http://www.osvdb.org/96019>)  


### Background

[Firefox](<http://www.mozilla.com/en-US/firefox/>) is a freely available web browser for multiple platforms including Windows, Linux, and Mac OS. 

### Problem

A vulnerability in the implementation of the crypto.generateCRMFRequest javascript method allows command execution when a user opens a specially crafted page in Firefox. 

### Resolution

[Upgrade](<https://www.mozilla.org/firefox>) to Firefox 23.0 or higher. 

### References

<https://www.mozilla.org/security/announce/2013/mfsa2013-69.html>  


### Limitations

Exploit works on Firefox 15.0 through 22.0 and requires a user to load the exploit page in Firefox. 

### Platforms

Windows  
Linux  
Mac OS X