Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Missing Mozilla Firefox flaw revealed in 2.0.0.20 release

sr-firefox3.jpg
From the "did you guess that?" files:

Mozilla has revealed the 'mysterious' clerical error missing flaw that it omitted from the Firefox 2.0.0.19 release earlier this week. It's the Cross-domain data theft via script redirect error message dealt with in Mozilla Foundation Security Advisory 2008-65

This is a "High" impact vulnerability that if exploited could potentially have been used by a malicious website to steal private data from users who are authenticated on the redirected website.  The attack would have needed a same-domain JavaScript URL that would have redirects victims to a different domain that contain non-parsable JavaScript.

I personally to date have not seen a weaponized version of this attack (though it doesn't on the surface sound to be to difficult to build). Kudos to Mozilla for admitting they made an error here though - and more importantly for fixing it so quickly.

Now Firefox 2.x can finally be put to rest. 

I am however curious as to whether or not this same attack is possible in Firefox 3.1 Beta 2 which was not updated for this fix (Firefox 3.0.0.5 was). Firefox 3.1 however uses the Tracemonkey JavaScript engine and has many security enhancements in it over the regular Firefox 3.x browsers.

| Comments (1) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Missing Mozilla Firefox flaw revealed in 2.0.0.20 release.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/6109

1 Comments

Dan Veditz said:

Firefox 3.1b2 also contains the fix.

Leave a comment