Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Firefox 3.0.2/2.0.0.17 fixes critical flaws

sr-firefox3.jpg
From the "time to update" files:

Mozilla has issued four security advisories as part of its Firefox 3.0.2 and 2.0.0.17 updates, two of which are labelled as critical.

MFSA 2008-41 details a privilege escalation issue by way of the XPCnativeWrapper. The flaw could potentially have allowed a maliciously crafted XSLT to create/run scripts that don't get validated.

MFSA 2008-42 is an advisory that is seemingly common with Mozilla, it's a "Crashes with evidence of memory corruption" issue. The interesting part this time around (for me at least) is that some of these crashes were reported by Apple to Mozilla. The Mozilla advisory notes that, "Drew Yao of Apple Product Security reported two crashes in Mozilla image rendering code."  Good to hear the Apple is sharing security information with Mozilla (and vice versa).

On the less critical but still interesting security side is a flaw titled "forced mouse drag." MFSA 2008-40 explained that:
Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Firefox 3.0.2/2.0.0.17 fixes critical flaws.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/5317

Leave a comment