Go Back   Club CDFreaks - Knowledge is Power > International Chat: General Topics > Latest News Headlines


Commercial ads

Latest News Headlines Discuss, *Critical Flaw Found in Firefox* at International Chat: General Topics forum; Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned. The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system. A patch is expected shortly, but in the meantime users can protect


Reply
 
Thread Tools
Old 10-05-2005   #1 (permalink)
CDFreaks Resident
 
DJMind's Avatar
 
Join Date: Jan 2005
Location: Arkansas, USA
Posts: 1,836
*Critical Flaw Found in Firefox*

Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.

The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.

A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.
Two Vulnerabilities Found

The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.

Source
__________________
DigitalLiquid Productions - http://www.digitalliquid.tk

AMD Athlon 64(tm) 3000+ Venice w/ 1GB PC3200 SDRAM
Seagate Barracuda (80GB) x2
JLMS XJ-HD166S + Nutech DVDRW DDW-082 + LiteOn SOHW-1693S
NVIDIA GeForce 6800GS
Soundblaster Live!
Microsoft Windows XP Professional (Service Pack 2)
DJMind is offline   Reply With Quote
Alt Today
Beitrag
__________________
This advertising will not be shown to registered members.
Register your free account today and become a member on Club CD Freaks - Knowledge is Power
Reply


If you can't find where you are looking for, then become a member and get an answer fast! We have thousands of people online every moment of the day to help you! Click here


Can't find where you are looking for? Search our knowledgebase!
 




Similar Threads
Thread Thread Starter Forum Replies Last Post
Non critical backups Kevatcrewe Blank Media 6 03-03-2006 11:15
Hackers work to exploit latest Firefox flaw pollushon Latest News Headlines 0 14-09-2005 04:43
Flaw on disc? mparter Blank Media 3 21-11-2004 16:12
Critical Error beginner123 General Software 1 16-10-2004 13:09
Optodisc DVD+R possible flaw rdgrimes Blank Media 7 10-02-2004 20:08


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +2. The time now is 16:08.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0