Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Mozilla Firefox 3.0.6 fixes six bugs

sr-firefox3.jpg
From the 'time to update' files:

Mozilla is out with its first Firefox update of 2009. Firefox 3.0.6 fixes at least six vulnerabilities, with only one tagged by Mozilla as being critical.

The on critical bug is a crash with evidence of memory corruption issue, which is something that I see in nearly every Firefox update. Mozilla doesn't provide a great deal of detail in its advisory on the issue - but that's a good thing since in this case the only purpose it would likely serve is for someone to reverse engineer and attack.

Firefox 3.0.6 also plugs a Cross Site Scripting (XSS) issue whereby the JavaScript could be executed within the context of another website, violating the same origin policy.

Perhaps more troubling to me is an issue only rated as 'High' by Mozilla for a Local File stealing issue related to the SessionStore function. According to Mozilla's advisory:
"An attacker could set an input control's text value to the path of a local file whose location was known to the attacker. If the tab was then closed and the victim persuaded to re-open it, upon restoring the tab the attacker could use this vulnerability to change the input type to file. Scripts in the page could then automatically submit the form and steal the contents of the user's local file."
Then there is a fix for a fix (Mozilla tends to have a few of these in any year -- hey it happens).  Firefox 3.0.4 fixed  that could have enabled an attacker to steal user information from local shortcut files.Apparently the flaw fix could be bypassed according to Mozilla so they've updated the fix to further mitigate risk.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Mozilla Firefox 3.0.6 fixes six bugs.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/6531

Leave a comment