Mozilla Firefox Multiple Vulnerabilities


Recommended Posts

Mozilla Firefox Multiple Vulnerabilities Secunia Advisory: SA33799

Release Date: 2009-02-04

Critical: crit_4.gif Highly critical

Impact: Security Bypass

Cross Site Scripting

Exposure of system information

Exposure of sensitive information

System access

Where: From remote Solution Status: Vendor Patch

Software:Mozilla Firefox 3.x

Subscribe: Instant alerts on relevant vulnerabilities lock.gif

CVE reference:CVE-2009-0352

CVE-2009-0353

CVE-2009-0354

CVE-2009-0355

CVE-2009-0356

CVE-2009-0357

CVE-2009-0358

Description:

Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious, local users to potentially disclose sensitive information, and by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, disclose sensitive information, or potentially to compromise a user's system.

1) Multiple errors in the layout engine can be exploited to cause memory corruptions and potentially execute arbitrary code.

2) Multiple errors in the Javascript engine can be exploited to cause memory corruptions and potentially execute arbitrary code.

3) A chrome XBL method can be used in combination with "window.eval" to execute arbitrary Javascript code in the context of another web site

Solution:

Update to version 3.0.6.

Secunia Advisories for full details - http://secunia.com/advisories/33799/

Link to post
Share on other sites

4 February 2009, 10:36

Firefox 3.0.6 fixes vulnerabilities

Firefox 3.0.6 has been released, fixing several vulnerabilities in the open source browser. Version 3.0.6 fixes six bugs, one of which is an issue related to JavaScript that affects the browsers layout engine. The update fixes a critical vulnerability, also found in Mozilla's Thunderbird e-mail client and the SeaMonkey Internet Suite, which can allow an attacker to gain access to exploited machines.

The update improves stability and improves scripting commands, including those found in popular extensions like Adblock Plus. For privacy, the client user ID has now been removed from the crash reports. Firefox 3.0.6 is available to download, or Firefox users can use the Firefox update service by selecting Help, then Check For Updates.

See also:

(crve)

Heise security: http://www.heise-online.co.uk/security/Fir...s--/news/112555

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...