On CBS.com: Prank Friends With Barney's HIMYM App
BNET Business Network:
BNET
TechRepublic
ZDNet

March 4th, 2009

Mozilla plugs Firefox code execution holes

Posted by Ryan Naraine @ 5:05 pm

Categories: Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Firefox, Mozilla, Open source, Patch Watch, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Mozilla Firefox, Vulnerability, Web Browser, Mozilla Corp., Web Browsers, Security, Web Site Development, Internet, Ryan Naraine

Mozilla today shipped Firefox 3.0.7 with fixes for at least eight security flaws, some rated critical.

The most serious of the vulnerabilities could be exploited by attackers to run code and install software, requiring no user interaction beyond normal browsing, Mozilla warned in a series of security advisories.

Here’s the skinny on the latest batch of Firefox band-aids:

[ SEE: Talking Firefox security with Mozilla’s Window Snyder ]

  • MFSA 2009-11 (Low risk) Mozilla contributor Masahiro Yamada reported that certain invisible control characters were being decoded when displayed in the location bar, resulting in fewer visible characters than were present in the actual location. An attacker could use this vulnerability to spoof the location bar and display a misleading URL for their malicious web page.
  • MFSA 2009-10 (Critical) libpng maintainer Glenn Randers-Pehrson reported several memory safety hazards in PNG libraries used by Mozilla. These vulnerabilities could be used by a malicious website to crash a victim’s browser and potentially execute arbitrary code on their computer. libpng was upgraded to a version which contained fixes for these flaws.
  • MFSA 2009-09 (High risk) Mozilla security researcher Georgi Guninski reported that a website could use nsIRDFService and a cross-domain redirect to steal arbitrary XML data from another domain, a violation of the same-origin policy. This vulnerability could be used by a malicious website to steal private data from users authenticated to the redirected website.
  • MFSA 2009-08 (Critical) An anonymous researcher, via TippingPoint’s Zero Day Initiative program, reported a vulnerability in Mozilla’s garbage collection process. The vulnerability was caused by improper memory management of a set of cloned XUL DOM elements which were linked as a parent and child. After reloading the browser on a page with such linked elements, the browser would crash when attempting to access an object which was already destroyed. An attacker could use this crash to run arbitrary code on the victim’s computer.
  • MFSA 2009-07 (Critical)  Four different vulnerabilities leading to browser crashes with evidence of memory corruption.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 5 Talkback(s)
RE: Mozilla plugs Firefox code execution holes
You can see how effectively firefox security updates are rolled out to end-users here: Read the rest)
Posted by: caffeinejolt Posted on: 03/08/09  (Edited: 03/08/09 @ 11:23) You are currently: a Guest | | Terms of Use
Ryan, any information on when these vulnerabilities  mhenriday | 03/05/09
You should be able to obtain this information from the advisories.  ye | 03/05/09
RE: Mozilla plugs Firefox code execution holes  dracomaster | 03/06/09
RE: Mozilla plugs Firefox code execution holes  TroyW | 03/06/09
RE: Mozilla plugs Firefox code execution holes  caffeinejolt | 03/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc