First "Extremely Critical" Firefox bug

Open discussion about any topic, as long as you abide by the rules of course!
Post Reply
Fender
Posts: 5876
Joined: Sun Jan 14, 2001 8:00 am

First "Extremely Critical" Firefox bug

Post by Fender »

http://wldj.sys-con.com/read/83666.htm
A security flaw that allows a malicious site to execute arbitrary code on a user's system has been discovered in Mozilla Firefox, Mozilla has reported. It appears to be the first "Extremely Critical" Firefox flaw logged by Secunia, Mozilla says.

The advisory explains that a successful attack involves exploiting two flaws: one involves tricking Firefox into thinking a software installation is being triggered by a whitelisted site, while the other relies on the software installation trigger not sufficiently checking icon URLs containing JavaScript code. The Secunia advisory suggests disabling JavaScript as a workaround; however, simply disabling software installation (Web Features panel of the Options/Preferences window in Firefox 1.0.3 or the Content panel in the latest trunk builds) eliminates the problem.

As the story was posted, Mozilla had not yet issued a patch. The only workaround it recommends is to disable Javascript.

If there's schadenfreude in Redmond, then there are big smiles. Firefox has been slowly eating away at Microsoft IE's market share, due in large part to its reputation as a safe browser not susceptible to the security flaws routinely found in Microsoft's dominant program.

Initial feedback at Mozilla's website was mixed. Where one poster pronounced himself "extremely disappointed," another said that "the press will hype up any security issue, (and) not necessarily in proportion to the severity and impact of it." With more than 50 million downloads of Firefox claimed by Mozilla, it's not doubtful that the browser becomes a more tempting target for bad guys and a better-debugged program by dint of the sheer mass of the increasing number of people who use it.
Grudge
Posts: 8587
Joined: Mon Jan 28, 2002 8:00 am

Post by Grudge »

1.0.4 is out now btw
Fender
Posts: 5876
Joined: Sun Jan 14, 2001 8:00 am

Post by Fender »

Nice. Fixes in 1.0.4:

MFSA 2005-44 Privilege escalation via non-DOM property overrides
MFSA 2005-43 "Wrapped" javascript: urls bypass security checks
MFSA 2005-42 Code execution via javascript: IconURL

How long did that patch take? 3 days? wow. :up:
glossy
Posts: 2282
Joined: Tue Apr 30, 2002 7:00 am

Post by glossy »

i should probably update from 0.8 :(
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

Updated. :icon14:

Mozilla needs to release incremental patches instead of full version upgrades for everything, and a way to deploy them remotely.
Denz
Posts: 2587
Joined: Thu Aug 17, 2000 7:00 am

Post by Denz »

Fire Fox looks like IE When it first came out, a fix every week.
Pext
Posts: 4257
Joined: Thu Aug 28, 2003 7:00 am

Post by Pext »

thanks for the info :icon14:
Post Reply