On CBS MoneyWatch: Deal or no deal? 8 lousy 'bargains'
BNET Business Network:
BNET
TechRepublic
ZDNet

February 22nd, 2007

Yet another 'critical' Firefox flaw

Posted by Ryan Naraine @ 7:41 pm

Categories: Browsers, Data theft, Exploit code, Firefox, Google, Microsoft, Mozilla, Open source, Patch Watch, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Mozilla Firefox, Flaw, Web Browser, Ryan Naraine

Less than 24 hours before the scheduled release of Firefox 2.0.0.2 as a high-priority browser refresh, a new “critical” vulnerability has been reported by Polish hacker Michal Zalewski.

Zalewski, who appears to be running an unofficial MOFFB (month of Firefox bugs) project, released a demo of a memory corruption issue that crashes the browser and puts users at risk of PC takeover attacks.

“Firefox is susceptible to a pretty nasty, and apparently easily exploitable memory corruption vulnerability. When a location transition occurs and the structure of a document is modified from within onUnload event handler, freed memory structures are left in inconsistent state, possibly leading to a remote compromise,” Zalewski warned.

Mozilla’s security team is tracking the issue.

Zalewski’s ongoing browser research has also uncovered a “quite nasty” flaw in Microsoft’s Internet Explorer 7.

He described the IE 7 issue as a “combination-type vulnerability” that allows the attacker to:

a) Trap the visitor in a Matrix-esque tarpit webpage that cannot be left by normal means (this is a known brain-damaged design of onUnload Javascript handlers),

b) Spoof transitions between pages so that the user thinks he actually managed to leave the affected site, and so that the URL bar displays other addresses we didn’t actually go to.

“This opens a plethora of spoofing/phishing scenarios,” Zalewski warned. A demonstration page is available for testing purposes.

So far this month, Zalewski’s demos have included focus bugs, a location.hostname issue (critical), a blank bug, a bookmark issue and today’s unload and trap flaws.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 16 Talkback(s)
May be fixed
Browsing the developer chatter associated with this test, it looks as though they may already have fixed it. I just updated FF a day or two ago and it refuses to crash when I click the link.... (Read the rest)
Posted by: Ginevra Posted on: 02/26/07 You are currently: a Guest | | Terms of Use
I'm betting on mozilla fixing their product first before microsoft .  Intellihence | 02/22/07
Unlikely.  hickum | 02/23/07
Sorry son , I don't do SPAM , like you would have others believe .  Intellihence | 02/23/07
I'm with hickum on this ine  John Zern | 02/23/07
The cult of retards...  Scrat | 02/23/07
I've said it before...  ju1ce | 02/23/07
You should try the widgets  nucrash | 02/23/07
I tried them...  ju1ce | 02/23/07
Treat Websites like ISO Compliance  nucrash | 02/23/07
Although agreed...  ju1ce | 02/23/07
Re: Although agreed...  memoimyself@... | 02/23/07
Convert from Firefox... (NT)  ju1ce | 02/26/07
Re: Treat Websites like ISO Compliance  memoimyself@... | 02/23/07
hmmm...  miketyler@... | 02/26/07
Mozilla also taking care of V1.5.0.nn users?  internot | 02/26/07
May be fixed  Ginevra | 02/26/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads