Newsletters Select newsletters below and click the button to sign up!
Internetnews BloggersRecent Entries
ArchivesMonthly ArchivesSearch The Blog
« Red Hat introduces Extended Update Support |
Sean Michael Kerner Blog
| I'm Linux video - Better than I'm a Mac, you're a PC? »
Missing Mozilla Firefox flaw revealed in 2.0.0.20 release From the "did you guess that?" files: Mozilla has revealed the 'mysterious' clerical error missing flaw that it omitted from the Firefox 2.0.0.19 release earlier this week. It's the Cross-domain data theft via script redirect error message dealt with in Mozilla Foundation Security Advisory 2008-65. This is a "High" impact vulnerability that if exploited could potentially have been used by a malicious website to steal private data from users who are authenticated on the redirected website. The attack would have needed a same-domain JavaScript URL that would have redirects victims to a different domain that contain non-parsable JavaScript. I personally to date have not seen a weaponized version of this attack (though it doesn't on the surface sound to be to difficult to build). Kudos to Mozilla for admitting they made an error here though - and more importantly for fixing it so quickly. Now Firefox 2.x can finally be put to rest.
I am however curious as to whether or not this same attack is possible in Firefox 3.1 Beta 2 which was not updated for this fix (Firefox 3.0.0.5 was). Firefox 3.1 however uses the Tracemonkey JavaScript engine and has many security enhancements in it over the regular Firefox 3.x browsers. 0 TrackBacksListed below are links to blogs that reference this entry: Missing Mozilla Firefox flaw revealed in 2.0.0.20 release. TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/6109 1 CommentsLeave a comment |
||
Firefox 3.1b2 also contains the fix.