Register   FAQ   Login  

Secunia advisory SA16911 -- Mozilla Firefox vulnerabilities





AddThis Social Bookmark Button AddThis Feed Button

       2-spyware forum index -> Web browsers
Author Message
_FRG_
Guest





Post Post subject: Secunia advisory SA16911 -- Mozilla Firefox vulnerabilities Reply with quote

This advisory was released more than one month ago. However, a lot of users are still running vulnerable Firefox versions. I have to warn them once again - update immediately! Vulnerabilities described in the advisory are very serious:

"Multiple vulnerabilities have been reported in Firefox, which can be exploited by malicious people to conduct spoofing attacks, manipulate certain data, bypass certain security restrictions, and compromise a user's system.

1) A boundary error in the processing of XBM images can be exploited to cause a heap based buffer overflow via a specially crafted image.

Successful exploitation allows execution of arbitrary code.

2) An error in the processing of Unicode sequences with "zero-width non-joiner" characters can be exploited to corrupt the stack and cause a crash.

Successful exploitation may allow execution of arbitrary code.

3) An input validation error in the processing of headers passed to the "XMLHttpRequest" object can be exploited to inject arbitrary HTTP requests.

4) An unspecified error where a XBL control which implements an internal interface can spoof DOM objects.

This is similar to vulnerability #8 in:
SA16043

5) An unspecified integer overflow error in the JavaScript engine can be exploited to execute arbitrary code.

6) The problem is that unprivileged "about:" pages can load privileged "chrome:" pages in certain situations.

This does not pose any security risk by it self, but can be exploited in combination with other cross-site scripting vulnerabilities to execute arbitrary code.

7) An error in the creation of windows can be exploited to open a new window without the address bar and status bar via a reference to a closed window.

Successful exploitation allows bypass of certain security mechanisms designed to protect against phishing attacks.

The vulnerabilities have been reported in version 1.0.6. Prior versions may also be affected."

DANGER: highly critical

SOLUTION: upgrade to Firefox 1.0.7
Thu Oct 27, 2005 9:14 am
Back to top
_FRG_
 
       2-spyware forum index -> Web browsers All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




Recommended software:
Spyware Doctor
(91/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and easy-to-manage...
SUPERAntiSpyware
(89/100)
SUPERAntiSpyware is a powerful, highly effective spyware remover introducing advanced parasite detection and removal features along with reliable real-time protection. The program is not...
CounterSpy
(85/100)
CounterSpy is a powerful spyware remover based on revolutionary hybrid engine, which incorporates traditional anti-spyware and advanced antivirus engines. Such combination allows CounterSpy...
Malwarebytes Anti Malware
(75/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such...
Windows Defender
(75/100)
Windows Defender is a free anti-spyware program made by the leading software company to add native spyware protection to its most popular product - the Microsoft Windows operating...
Encyclopedia of parasites: