Mozilla releases Firefox update 3.0.2; patch for security flaw included | Startup Meme - Technology Startup and Latest Tech News

Our comments and trackback policy You Link We Follow, You Comment We Promote

Sep 25 2008

Mozilla releases Firefox update 3.0.2; patch for security flaw included

Shoaib Hashmi 

Firefox Wordmark Horzontal - newlockupMozilla has released the latest update for Firefox i.e. Firefox 3.0.2 which contains a patch for 12 security flaws. Some of these flaws had put millions of internet users at the danger of having a remote code execution attack. According to Mozilla, the latest update contains two issues which are rated ‘critical’ by them. The flaw which is documented can be utilized to run code of the attacker and install the software without the intervention of user other than the usual browsing.

Following are some of the vulnerabilities as described by Mozilla Security Center:

MFSA 2008-40:

Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.

MFSA-2008-41:

Mozilla security researcher moz_bug_r_a4 reported a series of vulnerabilities by which page content can pollute XPCNativeWrappers and have arbitrary code run with chrome privileges. One variant reported by moz_bug_r_a4 only affected Firefox 2.

Mozilla developer Olli Pettay reported that XSLT can create documents which do not have script handling objects. moz_bug_r_a4 also reported that document.loadBindingDocument() returns a document that does not have a script handling object. These issues could also be used by an attacker to run arbitrary script with chrome privileges.

MFSA-2008-42:

Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

Drew Yao of Apple Product Security reported two crashes in Mozilla image rendering code. This vulnerability only affected Firefox 3.

David Maciejak of Fortinet’s FortiGuard Global Security Research Team also reported a crash in graphics rendering which only affected Firefox 3.

MFSA 2008-43:

Microsoft developer Dave Reed reported that certain BOM characters are stripped from JavaScript code before it is executed. This can lead to code, which would otherwise be treated as part of a quoted string, to be executed. The issue could potentially be used by an attacker to bypass or evade script filters and perform an XSS attack.

Security researcher Gareth Heyes reported an issue with the HTML parser in which the parser ignored certain low surrogate characters if they were HTML-escaped. This issue could potentially be used to bypass naive script filtering and used in an XSS attack. This issue only affected Firefox 2.

Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.

MFSA-2008-44:

Mozilla developer Boris Zbarsky reported that the resource: protocol allowed directory traversal on Linux when using URL-encoded slashes.

Mozilla developer Georgi Guninski reported that the restrictions imposed on local HTML files could be bypassed using the resource: protocol. The vulnerability allowed an attacker to read information about the system and prompt the victim to save the information in a file.

Other than this, Mozilla has also released a patch for several Firefox 2 vulnerabilities but the users are recommended strongly to upgrade to the latest Firefox.

  • Facebook
  • Digg
  • Reddit
  • del.icio.us
  • StumbleUpon
  • Twitter
  • E-mail this story to a friend!
blog comments powered by Disqus
popular body piercings butterfly dragonfly tattoo nikki reed tattoo picture wallpaper tattoo girl personal art tattoo xiaxue tattoo asian tattoo angels tattoo middlesbrough 14 tattoo new tattoo sleeping wonderbra lace tattoo military tattoo tv puncture piercings nick cave tattoo york tattoo parlour bob tyrell tattoo artist vancouver best tattoo artist names of tattoo parlors millenium tattoo fort collins modern ink tattoo shop oregon tattoo shops preview piercings wrist tattoo placement anchor tattoo benton pops tattoo shop vicenza tattoo norwalk tattoo studio point blank tattoo wisconsin dells appleton tattoo ace dragon tattoo hk owl tattoo careers as a tattoo artist new york tattoo best victoria s secret models tattoo mother love tattoo wylie tattoo outline tattoo flash valkyrie viking tattoo underworld tattoo ct anthem tattoo gainesville fl tragus piercings hurt small lip piercings wrist tattoo love dragon ankle tattoo unhinged tattoo old town tattoo pasadena phil tag tattoo northern pikes nice tattoo nautical tattoo momentum tattoo hawaii mike v tattoo wrist tattoo for men dove tattoo designs cloud tattoo moon tattoo gallery black lotus tattoo ri wrist tattoo word ideas tragus piercings aftercare voodoo tattoo studio gosford dolorosa tattoo studio valkyrie wing tattoo from max payne adam barton tattoo artist pixie back tattoo other world tattoo portia di rossi tattoo bmp tattoo nick cannon tattoo picture tiendas de piercings en mexico cheryl cole s hand tattoo women in tattoo photoshop tutorials tattoo original classic tattoo wrist tattoo heart new school flash tattoo play tattoo machine brontosaurus tattoo victoria brown tattoo coast guard tattoo policy too much ointment on tattoo colombian tattoo monk s tattoo devil tattoo ideas 3 kings tattoo wiki tattoo removal devil women tattoo black women tattoo navy tattoo pictures people tattoo designs normal tattoo prices charles wagner tattoo moms tattoo shop san francisco veldspar tattoo what can i use for tattoo ink unholy grail tattoo worcester ma rubins piercings easy tattoo bellevue phat dragon tattoo photoshop tattoo brushes free native warrior tattoo new beckham tattoo ace custom tattoo new zealand flag tattoo millenium tattoo buffalo zipper tattoo modern body art tattoo studio montreal canadian tattoo venus tattoo new york xavier roberts tattoo navy wings tattoo adorned tattoo nyc mami ink tattoo designs beer city tattoo convention 2008 yellow book tattoo nail tattoo designs nova scotia tattoo shops buy tattoo equipment caesar tattoo tongue piercings during pregnancy tongan shield tattoo does a tattoo on the back of the neck hurt allston tattoo old world tattoo underground tattoo olean ny voodoo doll tattoo florida military tattoo quotes ugly tattoo pics types piercings butterfly celtic tattoo aenigma tattoo boricuas tattoo x de medici tattoo woman cross tattoo ankh tattoo design miss ariana tattoo point of view tattoo moms millenium tattoo ink angel with sword tattoo morgan russell tattoo nyc tattoo license customs tattoo altoona wicked tattoo garden city phrase tattoo ideas tool maynard tattoo zoo tattoo cork phrases to tattoo michael gardner tattoo military sleeve tattoo narellan tattoo pin up fairy tattoo possible facial piercings phx tattoo donovan s tattoo norse runes tattoo toowoomba tattoo shops colortech tattoo ultimate tattoo torrent brighton tattoo convention nz tattoo museum paducah ky tattoo zoroastrian tattoo vanishing tattoo website uv eye tattoo women s tattoo t shirt new york city tattoo convention vancouver tattoo parlors peace sign in heart tattoo zoomorphic tattoo designs puma tattoo machine mother with child tattoo vampire tattoo blade mannen tattoo tony carbajal tattoo naval academy tattoo policy wrist tattoo bird new tattoo cleaning pink ribbon tattoo pics pinks tattoo on her left arm blue eyeball tattoo women s tattoo designs flowers chest girls tattoos pictures gal blood brothers tattoo ltd bad girl tattoo pennsylvania tattoo shops nicklas westin tattoo ucla tattoo a splash of color tattoo pink ribbon fake tattoo yan solo tattoo one life tattoo brainerd newcastle united tattoo designs bodyworks tattoo absolute tattoo in menomonee falls oui s tattoo manhattan tattoo angel wing wrist tattoo new world tattoo colorado wolf and feather tattoo cherry blossom tattoo on foot vegetable ink tattoo chest tattoo quotes alex franklin tattoo balrog tattoo plug tattoo tony morello tattoo phenix tattoo outside in tattoo removal ugliest belly button tattoo x tattoo on hand zune tattoo fail transgender tattoo y2j tattoo pour boiz tattoo traverse city orchid tattoo and piercing punk tattoo gallery pin up tattoo artists brady duncan tattoo olde city tattoo yashin tattoo van nuys tattoo what age to get a tattoo beelistic tattoo cincinnati zodiac tattoo pics purple frog tattoo yankee tattoo schiedam yakuza women tattoo pelvic star tattoo new traditions tattoo black bat tattoo zoo tattoo and piercing black art tattoo penticton pearl jam stickman tattoo pocono tattoo shop nice natural tits Aimee Desade Alanah Rae Melissa Jacobs Adriana Nevaeh Kelly Welch Abby Skyy pretty young girl Ahryan Astyn Charlotte Vale Aarolyn Barra Andy Sandimas skinny guy Sophia Lynn Adrenalynn fat ass Big Mouthfuls Eva Karera couple pussies Bangbros sites Tasha Lynn pocket pussy Tara Lee Lisa Lexington kind of homemade porn Aaliyah Jolie Alanna Ackerman Kalani Breeze Alana Leigh Cum Splashing young mom Abby Rode slutty girls in Halloween costumes Bait Bus Elena Cole Tessa Taylor Cock Suck And Cum dildo up her ass Esperanza Gomez booty bounce XOXO BRANDI Tugjobs hair woman fucking