On CHOW: How to avoid dirty looks at cafes
BNET Business Network:
BNET
TechRepublic
ZDNet

February 7th, 2008

Mozilla delivers patches for Firefox; Plugs flat file vulnerability

Posted by Larry Dignan @ 9:26 pm

Categories: Exploit code, Firefox, Mozilla, Open source, Patch Watch, Viruses and Worms, Vulnerability research

Tags: Mozilla Firefox, Vulnerability, Web Browser, Mozilla Corp., MFSA, Memory Corruption, Web Browsers, Security, Internet, Larry Dignan

Mozilla on Friday delivered its Firefox 2.0.0.12 update including patches that fix a Web forgery flaw, browsing history and forward navigation stealing and the directory traversal via chrome, which has been the most visible vulnerability of late.

According to the Firefox security advisory, Mozilla filed the following fixes in its flagship browser:

The most notable of the bunch is MFSA 2008-05. This fix covered that vulnerability that allowed an attacker to run off with stored cookies and other data contained in flat files. The vulnerability was discovered by researcher Gerry Eisenhaur. On Jan. 29, Mozilla security chief Window Snyder upgraded the vulnerability and set plans for Firefox 2.0.0.12. On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by Eisenhaur on Jan. 19.

Regarding the flat file flaw Mozilla said:

URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used “flat” packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.

Mozilla researcher moz_bug_r_a4 reported that this vulnerability could be used to steal the contents of the browser’s sessionstore.js file, which contains session cookie data and information about currently open web pages.

mozilla.png

Another critical flaw (MFSA-2008-06) was one that allowed the stealing of Web browsing and forward navigation stealing. Mozilla noted:

Mozilla contributor David Bloom reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes designMode frames. The reported issue can be used to steal a user’s navigation history, forward navigation information, and crash the user’s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.

And a third critical vulnerability (MFSA-2008-03) covered a “privilege escalation, XSS Remote Code Execution.”

Mozilla said:

Mozilla contributors moz_bug_r_a4 and Boris Zbarsky submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by moz_bug_r_a4 demonstrated that the XMLDocument.load() function can be used to inject script into another site, violating the browser’s same-origin policy.

And finally Firefox 2.0.0.12 addresses crashes due to memory corruption (MFSA-2008-01). Mozilla noted:

Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.

The remaining patches covered vulnerabilities that were deemed less critical. These vulnerabilities also affected Thunderbird and SeaMonkey.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 42 Talkback(s)
Firefox update
I updated the latest Firefox and have a bad problem with it opening multiple sessions .When it does this,it says Entering YahooBuildToolbar.I removed all of Yahoo and removed and reinstalled Firef... (Read the rest)
Posted by: roge Posted on: 02/10/08 You are currently: a Guest | | Terms of Use
Wow, sure was easy.  OButterball | 02/08/08
If it was like the last couple months... no reboots required for Vista  NonZealot | 02/08/08
Um, see, we're forced to use Windows XP...  OButterball | 02/08/08
Reboots are only necessary to changes in kernel.  osreinstall | 02/08/08
MS bashing for a Firefox problem?  transposeIT | 02/09/08
thanks; that is good information  Narr vi | 02/08/08
RE: Mozilla delivers patches for Firefox; Plugs flat file vulnerability  lennycald@... | 02/08/08
Why?  bart001fr | 02/08/08
It's like this  ilovebacon | 02/08/08
RE: Mozilla delivers patches for Firefox; Plugs flat file vulnerability  serv2meek@... | 02/08/08
There's a bad flaw in this update  serv2meek@... | 02/08/08
Problem is Norton  dl@... | 02/08/08
RE:FireFox Update, Bad News  b3tonyc@... | 02/08/08
Well-known problem  Greenknight_z | 02/09/08
Browser's fault?  joe.smetona@... | 02/08/08
Why do you say they all appear only on Windows?  NonZealot | 02/08/08
Reply.  joe.smetona@... | 02/08/08
FireFox Update, Bad News  b3tonyc@... | 02/08/08
Firefox update  roge | 02/10/08
FireFox Update, Bad News  b3tonyc@... | 02/08/08
RE:FireFox Update, Bad News  b3tonyc@... | 02/08/08
FireFox Update, Bad News  b3tonyc@... | 02/08/08
Possible Fix  joe.smetona@... | 02/08/08
RE:FireFox Update, Bad News  b3tonyc@... | 02/08/08
RE:FireFox Update, Bad News  b3tonyc@... | 02/08/08
Before Re-Installing.  joe.smetona@... | 02/08/08
extension?  LinuxandMacforlife | 02/08/08
So with all your multiple postings...  hasta la Vista, bah-bie | 02/08/08
how old is that article (NT)  kamahl928 | 02/08/08
Firefox Patch  bhelm@... | 02/08/08
It was painless for me too  Larry DignanZDNet Moderator | 02/08/08
Painless under Ubuntu too. Got it this morning.  DonnieBoy | 02/08/08
Mozilla delivers patches for Firefox  hal9001@... | 02/08/08
Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities  qmlscycrajg | 02/08/08
NEW flaw in Firefox 2.0.0.12  qmlscycrajg | 02/08/08
RE: Mozilla delivers patches for Firefox; Plugs flat file vulnerability  kevinkobayashi@... | 02/08/08
no Linux yet  LazLong | 02/08/08
Seven messages among the first 22,  mhenriday | 02/09/08
Seems Bogus  joe.smetona@... | 02/09/08
Firefox 2.0.0.12 information leak pOc  qmlscycrajg | 02/09/08
Firefox 2.0.0.12 information leak pOc  qmlscycrajg | 02/09/08
Mozilla Web info.  joe.smetona@... | 02/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here