Home > Security News > Critical Firefox, Safari flaws addressed
Security News:
EMAIL THIS

Critical Firefox, Safari flaws addressed

By SearchSecurity.com Staff
14 Nov 2008 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Mozilla and Apple released updates to their browsers this week, addressing serious flaws that could allow an attacker to access critical files and take control of a victim's computer.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

Mozilla released Firefox 3.04, addressing about 10 errors in previous versions of the popular Web browser. Four of the flaws were rated critical by Mozilla. Many of the flaws could be exploited by an attacker to access sensitive information and gain access to a user's machine.

Mozilla addressed memory corruption issues and browser engine errors that could cause the browser to crash. Several Firefox errors allow an attacker to pass malicious JavaScript code to bypass browser security restrictions.

Danish vulnerability clearinghouse Secunia issued an alert giving the flaws a highly critical rating. Secunia said the rating was given since an attacker could potentially exploit some of the flaws remotely and gain access to system information.

Meanwhile, Apple issued version 3.2 of its Safari browser this week, which could be exploited by an attacker to gain access to sensitive data and take control of a victim's system. Secunia gave the flaws a highly critical rating.

Apple addressed graphics handling errors that could cause a heap-based buffer overflow, crashing the browser. Image processing errors could allow an attacker to pass malicious code.

The French Security Incident Response Team (FrSIRT) issued an advisory giving the flaws a critical rating.

"These issues are caused by buffer overflow, uninitialized memory access, memory corruption, signedness and design errors when processing malformed data," FrSIRT said.



Tags: Web Browser SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Browser Security
Exploit code targets Internet Explorer zero-day display flaw
InZero Systems launches hardware-based security gateway
Web security firm ranks Firefox, Safari browsers as flaw prone
Microsoft fixes security update that breaks Internet Explorer
Mozilla update repairs Firefox buffer overflow vulnerabilities
Kaspersky system analyzes malicious URLs on Twitter for malware
Silon malware intercepts Internet Explorer sessions, steals credentials
Do Facebook URL security concerns justify blocking social networks?
Phishing attacks to remain a major problem, say security experts
Adrian Perrig: Improve SSL/TLS Security Through Education and Technology
Web Browser Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
honey monkey  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts