Home
Blog
Channel
Business
Enterprise
Networking
Security
Tech
Commentary
IT Jobs




Firefox Update Tackles Pair of Critical Bugs

Mozilla plugs holes while the march continues toward Firefox 3.

March 26, 2008
By Sean Michael Kerner: More stories by this author:

While Mozilla is busily developing its next-generation Firefox 3 open source Web browser, work continues to improve stability and security with the current Firefox 2.x.

A case in point is the new Firefox 2.0.0.13 release, which is accompanied by no less than six Mozilla Foundation Security Advisories -- two of them critical.

The critical bugs fixed in 2.0.0.13 include a JavaScript privilege escalation and arbitrary code execution issue. According to Mozilla's advisory, the problem relates to a series of flaws that could have allowed page scripts to run with elevated privileges.

By running with elevated privileges, the script could potentially have been used by an attacker to exploit a vulnerable system.

The potential exploit isn't new for Mozilla, which said in its advisory that the bug is a variant on a pair of issues previously fixed in 2007 with the Firefox 2.0.0.5 and the 2.0.0.8 releases.

The second critical bug fix by Mozilla in the latest release relates to memory corruption.

"Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products," Mozilla said in its advisory. "Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code."

The new release also addresses a unique spoofing vulnerability that could potentially be used by an attacker in a phishing exploit.

The flaw -- which Mozilla rated a "High" severity issue -- makes use of XML User Interface Language (XUL), the group's language for creating the browser user interface. The issue potentially enables an attacker to launch a borderless pop-up in front of a user's active browsing session.

According to Mozilla's advisory, which labels the problem as "XUL pop-up spoofing variant (cross-tab pop-ups)", the technique could be used to spoof a login prompt for a site opened in a different tab -- allowing the attacker to steal the user's login credentials for that site.

Mozilla also patched a second spoofing issue in Firefox 2.0.0.13.

The flaw, originally reported by security research rsnake on the sla.ckers.org site in January, hinges on spoofing HTTP Referrers -- HTTP elements that provide information on the Web location where a user originated before visiting a particular site or page.

The vulnerability affects referrers that include authentication credentials but lack user names. Those bad referrers could potentially be used for a Cross-Site Request Forgery (CSRF) attack.

Although the magnitude of the 2.0.0.13 update is somewhat less than in previous updates -- representing a decrease from the 10 fixes in February's 2.0.0.12 release -- the update continues efforts by Mozilla to lock down the current, stable Firefox 2.x release.

While one Mozilla team works to plug holes in Firefox 2.x, resources are also being poured into its next-generation Firefox 3 browser. Currently at its Beta 4 release a fifth Beta is expected by early next week.

TAGS: Mozilla, Firefox, open source, authentication, security



Security News Archives | Contact Sean Michael Kerner | Back to top

Channel Changes

Channel Has Huge Stake in Looming WiMAX Battle

The ambitious plan by Sprint, Clearwire, Google and several others to build a fast WiMAX network in the United States could end up having a tremendous impact on the channel, as well as being the last-gasp opportunity for WiMAX itself.

  Managing the Modern Network
Sponsored by HP
In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Business Service Management: Generate Revenue Through IT
Sponsored by HP
IT must now help organizations attract, retain and grow customer relationships and increase customer satisfaction. Business service management (BSM) helps lay the foundation by managing services in dynamic support of business requirements. Learn more. »
 
  Evaluating Software as a Service for Your Business
Sponsored by Webroot
Is Software as a Service just hype, or is something really going on here? See if your company can benefit as SaaS tries to change the face of the enterprise. »
 
  Storage Networking: Configuration and Planning
Sponsored by HP
The most critical part of setting up a SAN is configuring each individual disk array. This guide examines configurations for SAN-attached servers and disk arrays, and looks at the future of IP storage. »
 
  Is Your Disaster Recovery Plan Good Enough?
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and it is one of the most difficult tasks, since it includes local hardware and software, networking equipment, and a test plan. Learn how to get disaster recovery right. »
 

Channel Insight

The Proven Formula for Vendor and Partner Success

Vendors and reseller organizations are relatively well-run, rational businesses. Charles Watson, senior vice president of marketing and sales of Blueroads, explores why so many complications arise when these two groups start working together.


Click the Join button below to sign up to our newsletter!









JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES