On GameSpot: Black Wii Remote, Nunchuk hit US Nov. 16
BNET Business Network:
BNET
TechRepublic
ZDNet

July 14th, 2009

Remote code execution exploit for Firefox 3.5 in the wild

Posted by Dancho Danchev @ 11:55 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Exploit code, Firefox, Hackers, Malware, Metasploit, Mozilla, Patch Watch, Pen testing, Responsible disclosure, Zero-day attacks

Tags: Mozilla Firefox, Exploit, Web Browsers, Internet, Dancho Danchev

A zero day exploit (Firefox 3.5 Heap Spray Vulnerability) affecting Mozilla’s latest Firefox release has been published in the wild. Through an error in the processing of JavaScript code in ‘font tags’ malicious attackers could achieve arbitrary code execution and install malware on the affected hosts.

There’s no indication of its use on a global scale just yet, however due to the fact that the PoC is now public, it shouldn’t take long before cybercriminals embed it within the diverse exploits set of their web malware exploitation kits, allowing it to scale.

More details on the mitigation and the exploit itself:

“Mozilla Firefox is prone to a remote code-execution vulnerability.  Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions. The issue affects Firefox 3.5; other versions may also be vulnerable.

NOTE: Remote code execution was confirmed in Firefox 3.5 running on Microsoft Windows XP SP2. A crash was observed in Firefox 3.5 on Windows XP SP3.”

Additional testing courtesy of heise Security indicates the exploit crashed Firefox under Vista, and that when tested under Windows 7 RC1 a dialog abortion script appeared.

In terms of mitigation, NoScript works like charm, successfully detecting the PoC’s attempt to access file://.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 32 Talkback(s)
Oh my, another one that thinks linux authors invented security...
I employ anyone to find a person that can say they have gone as long, malware free and BSOD free, using windows. It can't be done.

I have a 2002 Toshiba laptop with XP professional and ... (Read the rest)
Posted by: xuniL_z Posted on: 07/21/09 You are currently: a Guest | | Terms of Use
install "noscript" now!  ~doolittle~ | 07/14/09
And we all know...  mechBgon | 07/14/09
over 50% of your trusted sites are compromised?  ~doolittle~ | 07/15/09
How do you know either side.  phatkat | 07/15/09
permanent fix was painfully simple  ~doolittle~ | 07/17/09
Shields Up!:Noscript? Check. Adblock? Check.  Dietrich T. Schmitz | 07/14/09
UAC? Check. Standard Privileged Accounts? Check.  ye | 07/14/09
Vista installed? check IE running in protected mode? check.  xuniL_z | 07/14/09
Hope you downloaded and installed those  jacarter3 | 07/15/09
Why? Vista users had nothing to worry about.  ye | 07/15/09
That kind of naivete is so frightening  jacarter3 | 07/15/09
Yet here I am, malware free.  ye | 07/15/09
As for now...  jacarter3 | 07/15/09
I didn't say it was an exclusive combination.  ye | 07/15/09
nt  xuniL_z | 07/15/09
I'm good, thanks anyway. Hope you get code....  xuniL_z | 07/15/09
You forgot to mention Opera  jacarter3 | 07/15/09
LOL! Once a month is "frequently"? Thanks, I needed a laugh. (nt)  ye | 07/15/09
Never assume...  jacarter3 | 07/15/09
So you're one of those people who know better.  ye | 07/15/09
I am one of those people  jacarter3 | 07/16/09
jacarter...you can say with a straight face.....  xuniL_z | 07/16/09
Missing the point again  jacarter3 | 07/16/09
You've not heard of WSUS? It's free and easy to setup.  xuniL_z | 07/17/09
Cods Wallop!!  An Old Man | 07/15/09
I use it  jacarter3 | 07/15/09
How can this be?  ye | 07/15/09
Linux server market was not earned or sold....and linux run FAA.....  xuniL_z | 07/16/09
You keep spreading that FAA FUD, now don't ya...  UAC nanny screen | 07/16/09
So Linux being used to guard sensitive secrets being hacked is fud???  xuniL_z | 07/17/09
RE: So Linux being used to guard sensitive secrets being hacked is fud???  xboxmods3077 | 07/19/09
Oh my, another one that thinks linux authors invented security...  xuniL_z | 07/21/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads