PDA

View Full Version : Extremely critical Firefox flaws


trubador
05-09-2005, 01:52 PM
Extremely critical Firefox flaws

Proving that its not just IE that holds the monopoly in serious security problems, two new vulnerabilities in Mozilla's Firefox Web browser have been rated "extremely critical." Seemingly, the vulnerabilities have the potential to allow an attacker to take control of a PC simply by getting a user to visit a malicious Web site.

Because proof-of-concept code has been leaked -- as were the vulnerabilities -- before a patch was ready, Mozilla recommended that Firefox users either disable JavaScript or lock down the browser so it doesn't install additional software, such as extensions or themes, from Web sites.

The vulnerabilities were discovered by a pair of security researchers, who had notified Mozilla earlier in the month, but were keeping mum until a patch was written. However, details of the vulnerabilities were leaked by someone close to one of the researchers.

It appears that it is possible to trick the browser into thinking a download is coming from one of the by-default sites permitted to install software automatically: addons.mozilla.org or update.mozilla.org. Changes have been made to the Mozilla update site to try to minimise any potential for damage, however the problem will not be fixed properly until we are given Firefox 1.0.4.

link (http://www.techspot.com/story17559.html)

eta_carinae
05-09-2005, 02:03 PM
The vulnerabilities were discovered by a pair of security researchers, who had notified Mozilla earlier in the month, but were keeping mum until a patch was written. However, details of the vulnerabilities were leaked by someone close to one of the researchers.

What a jerk! :g2f:

AyuRocks
05-09-2005, 02:38 PM
Yeah, Java was messing with Friefox and my comp, so I just fweakin' uninstalled it the other day, wasn't worth it. Luckily, doesn't appear that anything major happened.

JadedLegend3
05-09-2005, 03:40 PM
Wait, what do I do about this? Speak in small, non-technical words. :D

Kathleen
05-09-2005, 03:47 PM
I make sure that I do all of my updates manually anyways. I know the JAVA script you're talking about, and I had to do some tweaking after I did my last update. Hopefully, this next update of 1.0.4 will resolve the issues.

grinner
05-09-2005, 04:22 PM
not to really worry about this. The amount of flaws between FireFox and IE... is no comparison between the two. These errors right now are not being exploited and should be taken care of before there is hopefully any exploitation of the flaw. You have a good firewall and some very good anti-virus... just don't accept anything that you don't need to accept.

BaseLine
05-10-2005, 01:41 AM
Yeah, Java was messing with Friefox and my comp, so I just fweakin' uninstalled it the other day, wasn't worth it. Luckily, doesn't appear that anything major happened.

Actually, Javascript is not Java. Java is created by Sun Microsystems. Javascript is a distant cousin from Java created by Netscape. The current flaw in Firefox has to do with Javascript.

Wait, what do I do about this? Speak in small, non-technical words. :D

Wait for a patch. :)

soyarma
05-10-2005, 01:51 AM
Use IE, lol.