Home > Information Security News > Mozilla patches 11 Firefox security flaws, JavaScript errors
Information Security News:
EMAIL THIS

Mozilla patches 11 Firefox security flaws, JavaScript errors

By Robert Westervelt, News Editor
12 Jun 2009 | SearchSecurity.com

Security UK News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Mozilla Foundation updated its Firefox browser late Thursday, deploying fixes to 11 vulnerabilities, including six critical flaws, mostly JavaScript related, which could be used by an attacker to run arbitrary code and gain access to system files.

Firefox 3.0.11 patches critical memory corruption errors, a race condition and a JavaScript chrome privilege escalation. Most user browsers will be updated automatically to the latest version.

In its list of advisories, Mozilla said the JavaScript chrome privilege escalation allows scripts from page content to run with elevated privileges. Several memory corruption errors were fixed, stabilizing the browser engine.

"Some of these crashes showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code," Mozilla said.

Mozilla said a race condition existed, allowing an attacker to write to freed memory under a certain condition if a person navigated away from a webpage during the loading of a Java applet. The browser maker also repaired a condition in which event listeners may be executed within the wrong JavaScript context.

"An attacker could potentially use this vulnerability to have a malicious event handler execute arbitrary JavaScript with chrome privileges," Mozilla said. Less critical vulnerabilities included:

  • CVE-2009-1834: URL spoofing with invalid unicode characters. An error exists allowing an attacker to display part of an Internationalized Domain Name as whitespace in the location bar, allowing an attacker to spoof a URL. Mozilla rated the flaw low.

  • CVE-2009-1835: Arbitrary domain cookie access by a local file. Mozilla said this flaw required a lot of user interaction to be exploited by an attacker. A user would have to download a malicious file and open it in their browser. It could then steal arbitrary cookies from the victim's computer. The flaw was given a moderate rating.

  • CVE-2009-1839: Incorrect principal set for file. The vulnerability is difficult to exploit, according to Mozilla. It can be exploited if a user downloaded a malicious document and then opened another document in a directory of interest to the attacker before opening the attacker's file in the same window. This flaw was given a moderate rating.

  • CVE-2009-1840: XUL scripts bypass content-policy checks. Mozilla said content-loading policies were not checked before loading external script files into XUL documents. The flaw was given a low rating.

    Tags: Web Application SecuritySecure Coding and Application ProgrammingVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Web Application Security
    Social networking risks, benefits for enterprises weighed by RSA panel
    How to prevent Adobe hacks from affecting your organisation
    Securing Web applications with Web application firewalls
    CISOs take measured steps to reduce social media risks
    Google to pay for Chrome browser vulnerabilities
    Facebook, McAfee partner to fix social network security issues
    PDF attack code complicates security analysis, skirts detection
    Annual security reports offer some hope
    Firefox, Opera, Safari browsers top list of high risk software
    Active PDF attacks target Reader, Acrobat zero-day vulnerability

    Secure Coding and Application Programming
    Open source software security tops commercial apps, study finds
    Improving software with the Building Security in Maturity Model (BSIMM)
    How to prevent Adobe hacks from affecting your organisation
    SANS Institute, MITRE release new top 25 dangerous coding errors list
    Code complexity analysis: How to keep it simple
    Active PDF attacks target Reader, Acrobat zero-day vulnerability
    Software piracy group offers cash to whistleblowers
    SQL injection detection tools and prevention strategies
    Cross-site scripting explained: How to prevent attacks
    H.D. Moore speaks about Metasploit Project deal, Release 3.3

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Serious Organized Crime Agency  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts