Page 1 of 1

First "Extremely Critical" Firefox bug

Posted: Thu May 12, 2005 1:29 pm
by Fender
http://wldj.sys-con.com/read/83666.htm
A security flaw that allows a malicious site to execute arbitrary code on a user's system has been discovered in Mozilla Firefox, Mozilla has reported. It appears to be the first "Extremely Critical" Firefox flaw logged by Secunia, Mozilla says.

The advisory explains that a successful attack involves exploiting two flaws: one involves tricking Firefox into thinking a software installation is being triggered by a whitelisted site, while the other relies on the software installation trigger not sufficiently checking icon URLs containing JavaScript code. The Secunia advisory suggests disabling JavaScript as a workaround; however, simply disabling software installation (Web Features panel of the Options/Preferences window in Firefox 1.0.3 or the Content panel in the latest trunk builds) eliminates the problem.

As the story was posted, Mozilla had not yet issued a patch. The only workaround it recommends is to disable Javascript.

If there's schadenfreude in Redmond, then there are big smiles. Firefox has been slowly eating away at Microsoft IE's market share, due in large part to its reputation as a safe browser not susceptible to the security flaws routinely found in Microsoft's dominant program.

Initial feedback at Mozilla's website was mixed. Where one poster pronounced himself "extremely disappointed," another said that "the press will hype up any security issue, (and) not necessarily in proportion to the severity and impact of it." With more than 50 million downloads of Firefox claimed by Mozilla, it's not doubtful that the browser becomes a more tempting target for bad guys and a better-debugged program by dint of the sheer mass of the increasing number of people who use it.

Posted: Thu May 12, 2005 1:30 pm
by Grudge
1.0.4 is out now btw

Posted: Thu May 12, 2005 1:34 pm
by Fender
Nice. Fixes in 1.0.4:

MFSA 2005-44 Privilege escalation via non-DOM property overrides
MFSA 2005-43 "Wrapped" javascript: urls bypass security checks
MFSA 2005-42 Code execution via javascript: IconURL

How long did that patch take? 3 days? wow. :up:

Posted: Thu May 12, 2005 2:11 pm
by glossy
i should probably update from 0.8 :(

Posted: Thu May 12, 2005 2:29 pm
by R00k
Updated. :icon14:

Mozilla needs to release incremental patches instead of full version upgrades for everything, and a way to deploy them remotely.

Posted: Thu May 12, 2005 4:53 pm
by Denz
Fire Fox looks like IE When it first came out, a fix every week.

Posted: Thu May 12, 2005 5:34 pm
by Pext
thanks for the info :icon14: