ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Dirty dozen: Firefox ships patch for 12 security flaws

By | September 24, 2008, 6:38am PDT

Summary: Mozilla has released another point update for its flagship Firefox browser to provide fixes for at least 12 documented security vulnerabilities.  Some of the flaws put millions of Web surfers at risk of remote code execution attacks. The Firefox 3.0.2 update addresses two issues rated by Mozilla to be “critical,” meaning that the documented vulnerability can [...]

Firefox fixes critical security flawsMozilla has released another point update for its flagship Firefox browser to provide fixes for at least 12 documented security vulnerabilities.  Some of the flaws put millions of Web surfers at risk of remote code execution attacks.

The Firefox 3.0.2 update addresses two issues rated by Mozilla to be “critical,” meaning that the documented vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.

Here’s the skinny from Mozilla’s bulletins:

[ SEE: Talking Firefox security with Mozilla’s Window Snyder ]

  • MFSA-2008-40 - Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.
  • MFSA-2008-41 - Mozilla security researcher moz_bug_r_a4 reported a series of vulnerabilities by which page content can pollute XPCNativeWrappers and have arbitrary code run with chrome privileges. One variant reported by moz_bug_r_a4 only affected Firefox 2.  Mozilla developer Olli Pettay reported that XSLT can create documents which do not have script handling objects. moz_bug_r_a4 also reported that document.loadBindingDocument() returns a document that does not have a script handling object. These issues could also be used by an attacker to run arbitrary script with chrome privileges.
  • MFSA-2008-42 - Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Drew Yao of Apple Product Security reported two crashes in Mozilla image rendering code. This vulnerability only affected Firefox 3. David Maciejak also reported a crash in graphics rendering which only affected Firefox 3.
  • MFSA-2008-43 - Microsoft developer Dave Reed reported that certain BOM characters are stripped from JavaScript code before it is executed. This can lead to code, which would otherwise be treated as part of a quoted string, to be executed. The issue could potentially be used by an attacker to bypass or evade script filters and perform an XSS attack. Security researcher Gareth Heyes reported an issue with the HTML parser in which the parser ignored certain low surrogate characters if they were HTML-escaped. This issue could potentially be used to bypass naive script filtering and used in an XSS attack. This issue only affected Firefox 2.
  • MFSA-2008-44 -  Mozilla developer Boris Zbarsky reported that the resource: protocol allowed directory traversal on Linux when using URL-encoded slashes. Mozilla developer Georgi Guninski reported that the restrictions imposed on local HTML files could be bypassed using the resource: protocol. The vulnerability allowed an attacker to read information about the system and prompt the victim to save the information in a file.

[ ALSO SEE: Firefox scrambles to add ‘private mode’ browsing ]

The open-source group also released patches for multiple vulnerabilities affecting Firefox 2 but strongly recommends that users upgrade to Firefox 3.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

11
Comments

Join the conversation!

Just In

RE: Dirty dozen: Firefox ships patch for 12 security flaws
zafer12 18th Aug
Mt2 turk MMO PvP game download online game servers
metin2 - metin2 indir - metin2 hile - metin2 gm komutlari - metin2 at gorevleri
MMO online games, game related content turk mt2 pvp servers
metin 2 - pvp - server - knight
Mt2 turk MMO PvP game servers online
metin2 pvp sererler - serverlar - pvp serverler - metin2 pvp sererlar - pvp kenti

download http://www.metin2oyunu.org game servers online http://www.metin2pvpserver.net turk mt2 pvp servers http://www.metin2pvpserverlar.com
mt2
metin2 turk
mt2 turk
metin2 tr
Metin 2
alemt2 indir
alemt2 kaydol
alemt2
fancymt2 kaydol
fancy mt2
mt2 pvp
metin2 pvp
metin2 pvp serverler
pvp
metin2
serverler
serverler

metin2pvpserver
metin2 pvp server
metin2 pvpserver
metin2pvp server
metin2pvp
metin2 server


metin2pvpserverlar
metin2 pvp serverlar
metin2pvp serverlar
metin2 serverlar

face
facebook
0 Votes
+ -
Adobe Flash Beta 10 on Linux Stopped Crashing
MisterMiester Updated - 24th Sep 2008
Every since build version 3 of Firefox 3.0.2 Adobe 10 beta stopped crashing on Linux 32/64 bit systems. Flash now runs great on this release, except for some minor issues with accelerated graphics and nVidia proprietary drivers in full screen mode.
Feels faster, quicker.
0 Votes
+ -
It's so secure. At least that's what the zealots want you to believe.
0 Votes
+ -
Secure under Linux, not under Windows
Don Collins 25th Sep 2008
I know it's a cheap shot, but Fox IS secure under Linux, but not Windows. Under Windows a keylogger still works after this Fox security update. Under Linux keyloggers cannot get installed in the first place. The worst current exploit for Fox under Linux is the Flash clipboard hijack, which is nothing more than an ankle biting party trick with no system consequence at all. That will disappear under Flash 10.
0 Votes
+ -
Huh?
Greenknight_z 25th Sep 2008
What does a keylogger have to do with Firefox?
0 Votes
+ -
well you see, it's like this
bmerc 25th Sep 2008
When we talk about "security" we mean "preventing having something bad done to you."

A keylogger is an example of something bad that could be done to you by exploiting a browser vulnerability.

Make sense now?
Case in point: you.
0 Votes
+ -
Straw man
JDThompson 27th Sep 2008
transposeIT wrote:

OMG...can't be. OSS just can't have vulnerabilities. It's so secure. At least that's what the zealots want you to believe.
No credible person claims OSS is invulnerable. The advantage to using OSS is that when vulnerabilities are found, they tend to be fixed faster. If this were, say, a Microsoft product, you'd have to wait until the second Tuesday of the next month at the earliest to get them fixed.
0 Votes
+ -
Eh 12 ?
Alan Smithie 25th Sep 2008
Can anyone list the 12 as I can only count 5:

MFSA 2008-44 resource: traversal vulnerabilities
MFSA 2008-43 BOM characters stripped from JavaScript before execution
MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)
MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution
MFSA 2008-40 Forced mouse drag

2 critical, 2 moderate and 1low.
0 Votes
+ -
God forbid that actual facts interfere with a juicy headline.
Mt2 turk MMO PvP game download online game servers
metin2 - metin2 indir - metin2 hile - metin2 gm komutlari - metin2 at gorevleri
MMO online games, game related content turk mt2 pvp servers
metin 2 - pvp - server - knight
Mt2 turk MMO PvP game servers online
metin2 pvp sererler - serverlar - pvp serverler - metin2 pvp sererlar - pvp kenti

download http://www.metin2oyunu.org game servers online http://www.metin2pvpserver.net turk mt2 pvp servers http://www.metin2pvpserverlar.com
mt2
metin2 turk
mt2 turk
metin2 tr
Metin 2
alemt2 indir
alemt2 kaydol
alemt2
fancymt2 kaydol
fancy mt2
mt2 pvp
metin2 pvp
metin2 pvp serverler
pvp
metin2
serverler
serverler

metin2pvpserver
metin2 pvp server
metin2 pvpserver
metin2pvp server
metin2pvp
metin2 server


metin2pvpserverlar
metin2 pvp serverlar
metin2pvp serverlar
metin2 serverlar

face
facebook

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix