Critical flaws open up Firefox 2.0x to attack

  • Email a Friend
  • Print Page
Critical flaws open up Firefox 2.0x to attack
By Stefanie Hoffman
Jul 3, 2008 3:33 PM
Tags: Critical | flaws | open | up | Firefox | 2.0x | to | attack

Secunia researchers detected numerous security vulnerabilities in the Mozilla Firefox 2.0x Web browser, many of which enable malicious attackers to hack into vulnerable systems and either shut down or take complete control of a user's computer.

Secunia researchers detected numerous security vulnerabilities in the Mozilla Firefox 2.0x Web browser, many of which enable malicious attackers to hack into vulnerable systems and either shut down or take complete control of a user's computer.

Researchers at Secunia, a Copenhagen, Denmark-based security company specializing in vulnerability assessment and management, issued a security advisory Wednesday, warning users of multiple errors they deemed "highly critical."

If exploited, the critical vulnerabilities could potentially allow remote attackers to conduct cross-site scripting and spoofing attacks, bypass security restrictions, disclose sensitive or system information, potentially compromise a user's system, access a user's system or launch a denial of service attack, according to the advisory.

In order for the attack to be successful, a hacker would have to entice or trick a user into viewing a malicious Web page or downloading a file infected with malicious code. However, users are only susceptible to exploitation if they're running versions prior to 2.0.0.15, the advisory warned.

Altogether, the vulnerabilities include multiple memory corruptions errors in the layout and JavaScript engine, a flaw in the handling of unprivileged XUL documents, and a bug in the "mozIJSSubSciptLoader.LoadScript" function that allows remote attackers to run arbitrary code with Chrome privileges.

Other errors can only be successfully exploited if an add-on using the affected function is installed. Those include multiple flaws in the block reflow process, the processing of file URLs contained within local directory listings, errors in the implementation of the JavaScript same origin policy and a glitch in the JAR file verification.

Additional errors can be found in the implementation of file upload forms and in the implementation of Java LiveConnect on Mac OS X. An uninitialized memory access error in the process of improperly encoded "properties," and flaws in the processing of "Alt Names" provided by peer trusted certificates and in the handling of Windows URL shortcuts also enable attackers to launch spoofing attacks or to access sensitive information.

Security experts recommend that users apply the latest version of Firefox, 2.0.0.15, onto their computers in order to protect themselves from attack, which can be downloaded from the Mozilla Website.

See original article on CRN.com
 

Copyright (c) 2009 CMP Media LLC
All rights reserved.

 


Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment


Top Stories
Westan founder to sell and retire
Victor Aghtan to enjoy the good life: drink wine, build a house.
 
HP forced to change cash-back process by ACCC
HP Australia received over 190 complaints from customers over cash-back confusion.

 
Scam email hits the Australian Federal Police
No organisation is sacred in the eyes of online scammers.
 

Shortcutsall you need to know on...

  • NBN 
  • Windows 7 
  • Unified Communications 
  • Twitter 
  • Virtualisation 

Latest Comments

"Hi Cecil, Tony Lagan from Sony made it clear that is the very case. Thanks for your input. "
by lguan Jul 1, 2009 6:33 PM
 
"Cool, I shall jump in my DeLorean right away, and head off to the Google developer day :-) Back ..."
by jgcertified Jun 30, 2009 10:11 PM
 
"A key issue for organisations is the complexity of licensing, particularly with the wide range ..."
by easysam Jun 30, 2009 6:50 PM
 
"All these $150-$200 predictions assume that $40 million will be paid by home and small business ..."
by peterh_oz Jun 30, 2009 5:06 PM
 
"I read eon below link unencrypting takes along time and another limitation appears to be if ..."
by kWAT Jun 30, 2009 9:56 AM
 

Polls

Has dealing with email security become easier?


   |   View results
The war on junk viruses is never ending, just when one thing is fixed another pops up
  38%
 
Hardware and software has become better at dealing with spam, fake email and virus attachments
  42%
 
Users are the key to dealing with email deluge they just need to be smarter about it
  20%
TOTAL VOTES: 50

Vote now

CRN Magazine

Issue: 268 | June, 2009

CRN Magazine looks in-depth at the emerging issues and developments for the Channel, and provides insight, analysis and strategic information to help resellers better run their businesses.