Firefox 3.0.4 - security related

ImageNews from out there about new technologies.

It will be updated when possible.

Firefox 3.0.4 - security related

Postby Juanm on Sunday November 16th, 2008 11h00:36

F was unleashed on November 12th.

Fixes from FF 3.0.3
Stat: 4 critical, 2 high, 2 moderate, 1 low.

Upgrading is highly recommended.
Disabling javascript in Mozilla Thunderbird too, at least until a new version comes out

  • MFSA 2008-58 Parsing error in E4X default namespace
  • MFSA 2008-57 -moz-binding property bypasses security checks on codebase principals
  • MFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violation
  • MFSA 2008-55 Crash and remote code execution in nsFrameManager
    ling and wushi of team509, via TippingPoint's Zero Day Initiative program, reported a flaw in part of Mozilla's DOM constructing code. This vulnerability can be exploited by modifying certain properties of a file input element before it has finished initializing. When the blur method of the modified input element is called, uninitialized memory is accessed by the browser, resulting in a crash. This crash may be used by an attacker to run arbitrary code on a victim's computer.
  • MFSA 2008-54 Buffer overflow in http-index-format parser
    Justin Schuh of the IBM X-Force reported a flaw in the way Mozilla parses the http-index-format MIME type. By sending a specially crafted 200 header line in the HTTP index response, an attacker can cause the browser to crash and run arbitrary code on the victim's computer.
  • MFSA 2008-53 XSS and JavaScript privilege escalation via session restore
    Security researcher David Bloom reported that the browser's session restore feature can be used to violate the same-origin policy and run JavaScript in the context of another site. Any otherwise unexploitable crash can be used to force the user into the session restore state
    Mozilla security researcher moz_bug_r_a4 demonstrated that this vulnerability could also be used by an attacker to run arbitrary JavaScript with chrome privileges.
  • MFSA 2008-52 Crashes with evidence of memory corruption (rv:1.9.0.4/1.8.1.18)
    Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
    NOTE: Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.
  • MFSA 2008-51 file: URIs inherit chrome privileges when opened from chrome
  • MFSA 2008-47 Information stealing via local shortcut files
Juanm

Phpbb related: looking 4 a MOD? :: phpBB bugtracker :: phpBBsecurity tracker :: phpBB knowledge base

D-Off @ MobileReview wrote:who cares about WAP anymore? :)
Try google and search for content
User avatar
Juanm
Site developer
Site developer
 
Posts: 763
Joined: Thursday March 25th, 2004 21h45:21
Location: Behind YOU



Ad
Bot
 


Similar topics


Return to Tech news

Who is online

Users browsing this forum: No registered users and 0 guests

cron

Rate this site