Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Mozilla fixes two critical Firefox flaws
SearchSecurity.com ^ | 31 Jul 2007 | SearchSecurity.com Staff

Posted on 07/31/2007 6:56:31 AM PDT by holymoly

The makers of Firefox Monday released a new version of the Web browser that addresses a pair of flaws.

The Mozilla Foundation has released Firefox version 2.0.0.6, addressing critical flaws that involved unescaped URLs passing to external programs and privilege escalation through chrome-loaded about:blank windows.

Last week, independent security researcher Billy Rios, said in an update on his blog that an input validation error could be delivered through the Firefox browser, enabling full access to the machine..

"You simply have to have IE7 installed somewhere on your system for this to work (which is basically most WindowsXP Sp2 systems)," he said.

Danish vulnerability clearinghouse Secunia rated the flaw "highly critical" in its 26201 advisory Thursday because attackers could exploit it remotely. Secunia said users must visit a malicious Web site in order for the flaw to be exploited successfully.

"The vulnerability is caused due to an input validation error within the handling of system default URIs with registered URI handlers (e.g. 'mailto', 'news', 'nntp', 'snews', 'telnet')," Secunia said in its advisory.

Secunia said the vulnerability is confirmed on a fully patched Windows XP SP2 and Windows Server 2003 SP2 system using Firefox version 2.0.0.5 and Netscape Navigator version 9.0b2.

The United States Computer Emergency Readiness Team (US-CERT) also issued a US-CERT 783400 advisory, warning that Mozilla Firefox fails to properly filter input when sending certain URIs to registered protocol handlers.

"This vulnerability may allow a remote, authenticated attacker to execute commands on a vulnerable system," the agency said in its advisory.


TOPICS: Chit/Chat; Computers/Internet
KEYWORDS: firefox; mozilla
Heads up.
1 posted on 07/31/2007 6:56:33 AM PDT by holymoly
[ Post Reply | Private Reply | View Replies]

To: holymoly

Just installed the new version 2 seconds ago. My “tabs” weren’t working at all this morning. Must be why. Things seem OK now. Phew!


2 posted on 07/31/2007 7:03:34 AM PDT by Daffynition (The quieter you become, the more you are able to hear.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; PenguinWry; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; ..

3 posted on 07/31/2007 7:16:21 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Linux users seem not to be affected by this since these are Windows-based issues.


4 posted on 07/31/2007 7:30:56 AM PDT by Clara Lou (Thompson '08-- imwithfred.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Clara Lou

Well it is a firefox issue but one that needs a certain environment to be attacked (Windows and IE7).


5 posted on 07/31/2007 7:50:23 AM PDT by N3WBI3 (Light travels faster than sound. This is why some people appear bright until you hear them speak....)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Clara Lou
Linux users seem not to be affected by this since these are Windows-based issues.

It also appears to be a Windows XP & Vista problem. (IE7 is unavailable for Windows 2000 & earlier.)

6 posted on 07/31/2007 7:56:50 AM PDT by holymoly
[ Post Reply | Private Reply | To 4 | View Replies]

To: holymoly

That would explain why Firefox keeps griping at me to restart.


7 posted on 07/31/2007 7:58:01 AM PDT by CholeraJoe (WARNING: Dangerous to pregnant women and small children. May burst into flames at any time.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson