Pages: 1

Those using Firefox or any mozilla products

(Click here to view the original thread with full colors/images)


Posted by: bread

Multiple Vulnerabilities in Mozilla Products

Quote:
National Cyber Alert System

Technical Cyber Security Alert TA06-038A


Multiple Vulnerabilities in Mozilla Products

Original release date: February 7, 2006
Last revised: --
Source: US-CERT


Systems Affected

Mozilla software, including the following, is affected:
* Mozilla web browser, email and newsgroup client
* Mozilla SeaMonkey
* Firefox web browser
* Thunderbird email client


Overview

Several vulnerabilities exist in the Mozilla web browser and derived
products, the most serious of which could allow a remote attacker to
execute arbitrary code on an affected system.


I. Description

Several vulnerabilities have been reported in the Mozilla web browser
and derived products. More detailed information is available in the
individual vulnerability notes, including:


VU#592425 - Mozilla-based products fail to validate user input to the
attribute name in "XULDocument.persist"

A vulnerability in some Mozilla products that could allow a remote
attacker to execute Javascript commands with the permissions of the
user running the affected application.
(CVE-2006-0296)


VU#759273 - Mozilla QueryInterface memory corruption vulnerability

Mozilla Firefox web browser and Thunderbird mail client contain a
memory corruption vulnerability that may allow a remote attacker to
execute arbitrary code.
(CVE-2006-0295)


II. Impact

The most severe impact of these vulnerabilities could allow a remote
attacker to execute arbitrary code with the privileges of the user
running the affected application. Other impacts include a denial of
service or local information disclosure.


III. Solution

Upgrade

Upgrade to Mozilla Firefox 1.5.0.1 or SeaMonkey 1.0.
For Mozilla-based products that have no updates available, users are
strongly encouraged to disable JavaScript.



Here are some FAQ for FireFox Installation
http://forums.mozillazine.org/viewtopic.php?t=106431

Should you get the "software installation is currently disabled" when installing any extentions.. read this,
http://kb.mozillazine.org/Unable_to...lation_disabled



Posted by: forwardone

It seems some other browsers aren`t as immune to attacks as we might have thought.



Posted by: clifton

Thanks for the warning, bread. I stick to Opera



Posted by: golddust

Thanks for the post bread. It was only a matter of time before these type of vunerabilities started showing up.
More users/time = hackers at work.

golddust



Posted by: disislery

Ok, it's a big problem of Firefox. But are you sure that any bwowser or e-mail client doesn't have such problems? I'm completely sure that Opera, IE (even 7th) has.
But if you use a good firewall and antivirus, you may use even IE 4 - I think the sogftware will protect you.



Posted by: ihsjnd7789

yes
time to update



Posted by: victortsoy

Agree with Disislery. Never browse internet without a firewall and antivirus. Even if you have all updates - your browser always have holes and mistakes (except Linux-based browsers)



Posted by: malinin

IMHO, firewqall is enough for Internet. You need antivirus only when open unknown files.



Posted by: mansur

Malinin - you are right - firewall is enough. I evene shut down my Kaspersky when I browse internet, because I have a good firewall.



Posted by: forwardone

Hmm, not a chance I`d like to take. I like every barrier up that I can possibly have when doing any sort of work on the `Net.



Posted by: Pete Berg

Thanks for this information friend and thanks for the warning that you have given in order to help us ...I am using firefox as browser and i need this kind of information that make me more clear about this browser and i found here such a very important knowledge about firefox that is very much important to me..Thanks again.




eXTReMe Tracker