Firefox Suffers 'Extremely Critical' Security Hole

Status
Not open for further replies.

ferrarif50

Journeyman
The Firefox Web browser has two unpatched security holes that could
allow an attacker to take control of a user's computer system, security
researchers have warned.

Firefox has two unpatched security holes that could allow an attacker to take control of a user's computer system, and exploit code is already circulating on the Internet, security researchers have warned.
A patch is expected shortly, but users can protect themselves in the meantime by switching off JavaScript. In addition, the Mozilla Foundation said it has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

The flaws were confidentially reported to the Foundation on May 2. But by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT).

Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

In recent months, Firefox has picked up market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that part of the reason the browser is more secure is because it has a relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.

The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

The Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, it warned that users may be vulnerable if they have added other sites to the whitelist.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," the Mozilla Foundation said in a statement published on Mozillazine.org.

Source: *www.computerworld.com/securitytopi...801,101624,00.html?source=NLT_ES_B&nid=101624
 

[flAsh]

In the zone
Thanx It seems Firefox is following the steps of MS IE havin serious bugs and late fixes as usual with MS
 
OP
ferrarif50

ferrarif50

Journeyman
rajesh said:
There we go again. Ferrarif50 and Firefox :p

There was no need of your fatous and a highly peevish comment rajesh.

This is just an innocent post telling about the latest flaw in Firefox, and just that.

For your information, I have a thread running in Tutorials, specially for security advisories and alerts, where I also put details about the flaws in IE and M$ software too.

I dont where you are trying to get at!! Trying to increase your post count?
:roll:
 

Choto Cheeta

Rebooting
many web site still doesnt support firefox....

i know this isnt our foult but a an user we will look to a brouser which can open all sites...
 

Charley

Just Do It
I had to uninstall Firefox , cos it encountered some problems during the month. And I'm happy with IE now.
 

hpotter606

Journeyman
Better use opera then or even maxthon. I found maxthon really good and fast too. Who cares about security!!!!!! I get virus from all , opera ,FF and IE but only when i am on c***k site.
 

goobimama

 Macboy
all I know is that since I've started using firefox, there have been no spyware installations, no viruses and no problems from the internet.
 

rajesh

Journeyman
ferrarif50 said:
rajesh said:
There we go again. Ferrarif50 and Firefox :p

There was no need of your fatous and a highly peevish comment rajesh.

I dont where you are trying to get at!! Trying to increase your post count?
:roll:

If i wanted to increase my post count I could go on to all posts and just confirm what others say in that post. For that matter look at my joining date and my poast count. I post only if I feel i have to make a point.

:evil: :evil: :evil: :evil:
 
Status
Not open for further replies.
Top Bottom