Home > Security News > Mozilla fixes nearly two dozen Firefox flaws
Security News:
EMAIL THIS

Mozilla fixes nearly two dozen Firefox flaws

By Bill Brenner, Senior News Writer
14 Apr 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The Mozilla Foundation has fixed approximately 21 flaws in the Firefox Web browser that could be exploited to bypass security restrictions, tamper with sensitive data or conduct cross-site scripting and phishing attacks.

Danish vulnerability clearinghouse Secunia rated the flaws "highly critical" in an advisory Thursday. The firm described the flaws as:

  • An error where JavaScript can be injected into another Web page that is currently loading. Attackers could exploit this to execute arbitrary HTML and script code in a user's browser session.
  • A garbage collection error in the JavaScript engine that can be exploited to cause memory corruption.
  • A boundary error in the CSS border rendering implementation that could be exploited to write past the end of an array.
  • An integer overflow in the handling of overly long regular expressions in JavaScript, which attackers could exploit to execute arbitrary JavaScript byte code.
  • Two errors in the handling of "-moz-grid" and "-moz-grid-group" display styles that could be exploited to execute arbitrary code.
  • An error in the "InstallTrigger.install()" method that be exploited to cause memory corruption.
  • An unspecified error that can be exploited to spoof the secure lock icon and the address bar by changing the location of a pop-up window in certain situations.
  • A condition where it's possible to trick users into downloading malicious files via the "Save image as..." menu option.
  • A condition where a JavaScript function created via an "eval()" call associated with a method of an XBL binding may be compiled with incorrect privileges. Attackers could exploit this to launch malicious code.
  • An error where the "Object.watch()" method exposes the internal "clone parent" function object, which can be exploited to execute arbitrary JavaScript code with escalated privileges.
  • An error in the protection of the compilation scope of built-in privileged XBL bindings that can be exploited to execute arbitrary JavaScript code with escalated privileges.
  • An unspecified error can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site via the window.controllers array.
  • An error in how a certain sequence of HTML tags are processed can be exploited to cause memory corruption.
  • An error in the "valueOf.call()" and "valueOf.apply()" methods can be exploited to execute arbitrary HTML and script code in a user's browser session.
  • Errors in the implementation of DHTML can be exploited to cause memory corruption.
  • An integer overflow error in the processing of the CSS letter-spacing property can be exploited to cause a heap-based buffer overflow.
  • An error in the way file-upload controls are handled can be exploited to upload arbitrary files from a user's system by dynamically changing a text input box to a file upload control.
  • An unspecified error in the "crypto.generateCRMFRequest()" method can be exploited to execute arbitrary code.
  • An error in how scripts in XBL controls are handled can be exploited to gain chrome privileges via the "Print Preview" functionality.
  • An error in a security check in the "js_ValueToFunctionObject()" method can be exploited to execute arbitrary code via "setTimeout()" and "ForEach."
  • An error in the interaction between XUL content windows and the history mechanism can be exploited to trick users into interacting with a browser user interface, which is not visible.

    Users who update to Firefox versions 1.0.8 or 1.5.0.2 will be protected.

    Tags: Web Authentication and Access ControlWeb Browser SecurityEmail and Messaging Threats (spam, phishing, instant messaging)Web Server Threats and CountermeasuresWeb Application and Web 2.0 ThreatsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Web Authentication and Access Control
    Group to shed light on secure identity management threats
    How to confirm the receipt of an email with security protocols
    Schneier-Ranum Face-Off: Is Perfect Access Control Possible?
    Kaminsky reveals key flaws in X.509 SSL certificates at Black Hat
    Changing times for identity management
    How to use single sign-on for Web access control to prevent malware
    IBM USB banking device stops keyloggers, malware
    Can mutual authentication beat phishing or man-in-the-middle attacks?
    Could someone place a rootkit on an internal network through a router?
    Sun launches open source OpenSSO for identity management

    Web Browser Security
    Microsoft fixes security update that breaks Internet Explorer
    Mozilla update repairs Firefox buffer overflow vulnerabilities
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Do Facebook URL security concerns justify blocking social networks?
    Phishing attacks to remain a major problem, say security experts
    Adrian Perrig: Improve SSL/TLS Security Through Education and Technology
    New Bahama botnet evades search engines, fuels click fraud
    SANS: Application threats, website flaws pose biggest security threats
    Mozilla helps Adobe push out faster patches
    Web Browser Security Research

    Email and Messaging Threats (spam, phishing, instant messaging)
    Messaging security risks have upper hand on solutions
    Web-based attacks skyrocket, pirating sites surge, security firms say
    Pushdo botnet uses Facebook to spread malicious email attachment
    Scareware report highlights successful business model
    How to prevent phishing attacks with social engineering tests
    Phishing protection begins with training, antiphishing evangelist
    Phishing attacks to remain a major problem, say security experts
    Barracuda acquires Purewire expanding Web security reach
    FBI raids phishing crime ring, nearly 100 arrested
    Massive phishing scheme affects Microsoft Hotmail accounts
    Email and Messaging Threats (spam, phishing, instant messaging) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    knowledge-based authentication  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts