Home > Security News > Critical Firefox, Safari flaws addressed
Security News:
EMAIL THIS

Critical Firefox, Safari flaws addressed

By SearchSecurity.com Staff
14 Nov 2008 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Mozilla and Apple released updates to their browsers this week, addressing serious flaws that could allow an attacker to access critical files and take control of a victim's computer.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

Mozilla released Firefox 3.04, addressing about 10 errors in previous versions of the popular Web browser. Four of the flaws were rated critical by Mozilla. Many of the flaws could be exploited by an attacker to access sensitive information and gain access to a user's machine.

Mozilla addressed memory corruption issues and browser engine errors that could cause the browser to crash. Several Firefox errors allow an attacker to pass malicious JavaScript code to bypass browser security restrictions.

Danish vulnerability clearinghouse Secunia issued an alert giving the flaws a highly critical rating. Secunia said the rating was given since an attacker could potentially exploit some of the flaws remotely and gain access to system information.

Meanwhile, Apple issued version 3.2 of its Safari browser this week, which could be exploited by an attacker to gain access to sensitive data and take control of a victim's system. Secunia gave the flaws a highly critical rating.

Apple addressed graphics handling errors that could cause a heap-based buffer overflow, crashing the browser. Image processing errors could allow an attacker to pass malicious code.

The French Security Incident Response Team (FrSIRT) issued an advisory giving the flaws a critical rating.

"These issues are caused by buffer overflow, uninitialized memory access, memory corruption, signedness and design errors when processing malformed data," FrSIRT said.



Tags: Web Browser SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Web Browser Security
Researchers to demonstrate new EV SSL man-in-the-middle hacks
Security researchers develop browser-based darknet
Microsoft cracks down on click fraud ring
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
IT pros can detect, prevent website vulnerabilities, thwart attacks
Stolen FTP credentials likely in massive website attacks
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
Google study backs browser silent auto update feature
Web Browser Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
honey monkey  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts