Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Firefox 3.0.4 is out fixing some 'neat' flaws

sr-firefox3.jpgFrom the "weird and wacky ways browser can be exploited" files:

As I noted last week Firefox 3.0.4 is out now (technically late yesterday) fixing at least 9 security fixes four of which are labeled as "critical".

There are (as usual) some flawa that I consider to be really interesting - in that they are attack vectors that I just haven't heard off or seen before. One of them is a Cross Site Scripting (XSS) and JavaScript privilege escalation via a Firefox browser session restore.

I love the Session Restore feature as I'm the kind of user that always has 10+ tabs open all the time. To think that it could be used as a vehicle to exploit me is "interesting" to say the least.  According to Mozilla, as a result of that flaw potentially, "any otherwise unexploitable crash can be used to force the user into the session restore state."

Mozilla also provides a fix for a flaw that could have enabled an attacker to steal user information from local shortcut files. Shortcut files?! Really? Mozilla only labels this flaw as "moderate" since they view it as being a little complex to execute. The way the attack would work is that .url shortcut files could potentially be used to read local cache information if the user downloaded both an HTML file and a .url shortcut.

As part of the update Mozilla is also updating Firefox 2.x to 2.0.0.19 though it's clear that the Firefox 2.x's days are numbered. With Firefox 3.1 around the corner (the Beta 2 release is likely next week now with a test day scheduled for Friday), it will soon be time for Firefox 3.x users to upgrade too.

| Comments (2) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Firefox 3.0.4 is out fixing some 'neat' flaws.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/5810

2 Comments

jimbo said:

Maybe Firefox have hired some ex MS employees.
At least Firefox are fixing the problems.
I am pissed off at how many time I see an update for Windows Guarantee Advantage (to whom) nearly every update from MS has a WGA update, IE7 stills falls over at the drop of a hat. Outlook goes beserk if you have a large number of emails in the inbox. I have recently retired from Computer support work and I am slowly getting rid of the poxy MS programs. I am so glad they do not manufacture cars, the road toll would be horrendous.

Social_Flea said:

Is this a problem on all operating systems? I assume it is but Ubuntu, at least Hardy, has not updated to this release yet.

Why just change your browser and your mailer? Get rid of the Micro-crap!

Leave a comment