On The Insider: Justin Timberlake Headed to Harvard
BNET Business Network:
BNET
TechRepublic
ZDNet

June 18th, 2008

Code execution vulnerability found in Firefox 3.0

Posted by Ryan Naraine @ 3:57 pm

Categories: Arbitrary Code Execution, Botnets, Browsers, Exploit code, Firefox, Hackers, Mozilla, Patch Watch, Responsible disclosure, Viruses and Worms, Vulnerability research

Tags: Mozilla Firefox 3.0, Mozilla Firefox, Attacker, Vulnerability, Web Browsers, Security, Internet, Ryan Naraine

Code execution vulnerability found in Firefox 3.0It’s not all about world records for Firefox 3.0.

Just hours after the official release of the latest refresh of Mozilla’s flagship browser, an unnamed researcher has sold a critical code execution vulnerability that puts millions of Firefox3.0 users at risk of PC takeover attacks.

According to a note from TippingPoint’s Zero Day Initiative (ZDI) , a company that buys exclusive rights to software vulnerability data, the Firefox 3.0 bug also affects earlier versions of Firefox 2.0x.

Technical details are being kept under wraps until Mozilla’s security team ships a patch.

According to ZDI’s alert, it should be considered a high-severity risk:

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, permitting the attacker to completely take over the vulnerable process, potentially allowing the machine running the process to be completely controlled by the attacker. TippingPoint researchers continue to see these types of “user-interaction required ” browser-based vulnerabilities - such as clicking on a link in email or  inadvertently visiting a malicious web page.

It looks very much like the vulnerability researcher was hoarding this vulnerability and saving it for Firefox 3.0 final release to make the sale.

In the absence of a fix, Firefox users should practice safe browsing habits and avoid clicking on strange links that arrive via e-mail or IM messages.

There are no reports of this issue being exploited but,  if you are worried about being at risk of drive-by attacks, consider using a different browser.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 106 Talkback(s)
Opera limitation
Opera doesn't have Adblock, and probably never will (Read the rest)
Posted by: rodonn Posted on: 07/25/08 You are currently: a Guest | | Terms of Use
Or put your FF3 in a sandbox  D-T-Schmitz | 06/18/08
Wait!  compy386 | 06/18/08
OK StrongBad  D-T-Schmitz | 06/18/08
What?  Arm A. Geddon | 06/19/08
Thanks  D-T-Schmitz | 06/20/08
Sorry to hear that  Sluggo Fishmonger | 06/20/08
Yeh, well go have some cookies and milk  D-T-Schmitz | 06/20/08
Using the same logic, FF needs to implement Protected Mode  NonZealot | 06/18/08
Same Situation. Different Day. wink  D-T-Schmitz | 06/18/08
Well, those OSX users will probably be OK...  lostarchitect | 06/19/08
Actually Leopard users might be protected against the Gpcoder trojan.  ye | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  jiaz1 | 06/18/08
Funny isn't it ...  fr0thy2 | 06/19/08
maybe Mozilla should do better code reviews...  killerbunny | 06/19/08
the good thing is Mozila is quick with patches...  killerbunny | 06/19/08
He responded already...nt  ItsTheBottomLine | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  cnfrisch | 06/18/08
Good luck with that!!!  techboy_z | 06/19/08
As if that's going to help you....  eMJayy | 06/19/08
Vulnerability.......  danm50 | 06/19/08
IE 7 on Vista has Protected Mode which provides an additional...  ye | 06/19/08
Unbelievable!  maggietoo9 | 06/19/08
Online Advertising Data is the game.  joe.smetona@... | 06/19/08
Don't Forget Yahoo.  joe.smetona@... | 06/19/08
....  Linux User 147560 | 06/19/08
Non-event  AndyCee | 06/19/08
You know, that many eyes argument is looking pretty shaky...  wolf_z | 06/19/08
Actually it isn't shaky at all...  storm14k | 06/19/08
These so-called 'Researchers' who...  D-T-Schmitz | 06/19/08
Or...  bigsibling | 06/19/08
nah  ttocsmij | 06/19/08
Ummm...  kirogl | 06/19/08
Maybe...  balaknair | 06/19/08
Of course greed was his motive!  maggietoo9 | 06/19/08
Many dotted i's may spell Mississippi  DannyO_0x98 | 06/19/08
Many eyes contradiction  wolf_z | 06/19/08
Not really...  jasonp@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  ArnoldZiffle | 06/19/08
Yes!  ttocsmij | 06/19/08
Use NoScript extension  aussiedawg | 06/19/08
Sound advice...  eMJayy | 06/19/08
What's wrong with scripts?  masonwheeler | 06/19/08
What's wrong...  PantherDave | 06/19/08
Not just a script blocker..  eMJayy | 06/19/08
Flash as well as Script and...  maggietoo9 | 06/19/08
That's why I don't disable Java  voska1 | 06/19/08
WARNING: zdnet.com advertisings are spreading a malware  qmlscycrajg | 06/19/08
WARNING: zdnet.com advertisings are spreading a malware  kirogl | 06/19/08
zdnet.com please check your banners because there's an exploit  qmlscycrajg | 06/19/08
Since you're the only one complaining....  eMJayy | 06/19/08
there's a trojan on zdnet.com web site spreading via advertisings  qmlscycrajg | 06/19/08
Screen shots? URLs?  James T. Kirk | 06/19/08
not convinced...  eMJayy | 06/19/08
Do you have any add'l information??  Ryan NaraineZDNet Moderator | 06/19/08
look this screenshot:: file download request  qmlscycrajg | 06/19/08
qmlscycrajg, can you translate warning on screenshot?  Mike Hunt | 06/19/08
translation  qmlscycrajg | 06/19/08
Thanks! (NT)  Mike Hunt | 06/19/08
Oh Dear. That's not good.  D-T-Schmitz | 06/19/08
What do I think?  BitTwiddler | 06/19/08
Not Just the Seller of the Code  EBathory | 06/19/08
Huh?  cslycord@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  atari8bit@... | 06/19/08
How is this a Firefox problem?  Mike Hunt | 06/19/08
Avast Application scans web pages  maggietoo9 | 06/19/08
Thanks. Would it warn you...  Mike Hunt | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  wsmith@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  cosims@... | 06/19/08
How does one "use a different browser"  bbaston@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  jackadair@... | 06/19/08
To me it is obvious that the 'researcher' in question  mhenriday | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  maggietoo9 | 06/19/08
this is nothing less than a shakedown racket  pikeman666@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  argosy2@... | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  argosy2@... | 06/19/08
FF2.0.0.14 freezes A LOT  LBiege | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  maggietoo9 | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  clanclark@... | 06/19/08
Master Joe Says...  MasterJoe | 06/19/08
That's funny!  Mike Hunt | 06/19/08
question  TedKraan | 06/20/08
N othing B ut Microsoft !  Mike Hunt | 06/20/08
Tempest in a teacup  Mitch 74 | 06/19/08
That's what I thought  Mike Hunt | 06/19/08
Firefox  shane715 | 06/19/08
This can't be. Open source software is like a fortress in security...NOT.  transposeIT | 06/19/08
What operating systems?  Chad_z | 06/19/08
With Vista you don't gain admin rights either.  ye | 06/19/08
Not my Windows box  NonZealot | 06/19/08
This is an intentional hole...  jackbond | 06/19/08
RE: Code execution vulnerability found in Firefox 3.0  twaynesdomain | 06/19/08
The emperor's new clothes  tonymcs@... | 06/19/08
One good thing...  jackbond | 06/19/08
And yet MS still isn't perfect either? WTF!?  Mike Hunt | 06/20/08
Here is another serious FF3 problem. What is going on with them  ANON55335 | 06/19/08
Attempt at FUD  TedKraan | 06/20/08
RE: Code execution vulnerability found in Firefox 3.0  RM Edi | 06/20/08
RE: Code execution vulnerability found in Firefox 3.0  no_axe_to__grind | 06/20/08
Perhaps now you will stop slating IE  l_eeburgess@... | 06/21/08
**** DAMN IT! THAT'S JUST MY LUCK!  bendib | 06/23/08
WOW!!  Horus418 | 06/25/08
WOW  lynchjohn | 07/10/08
Oh! Sorry Forgot  Horus418 | 06/25/08
Opera doesn't have Adblock  rodonn | 07/25/08
Opera limitation  rodonn | 07/25/08
Maybe a bug in the Addon or XUL runner  eagle72al | 06/26/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here