LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 06-17-2008, 10:09 AM   #91
unSpawn
Moderator
 
Registered: May 2001
Posts: 20,993
Blog Entries: 44

Rep: Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239Reputation: 1239
Thumbs up Thanks!


Great job you've been doing the past years. Thanks.

Last edited by unSpawn; 06-17-2008 at 10:12 AM.
 
Old 06-17-2008, 01:44 PM   #92
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Thanks for all the thanks guys! You are all very welcome!

On that note, I point you toward a Mozilla bug report filled-out by Giorgio Maone (the author of the NoScript extension) a few days ago. I wasn't sure how real the security implications of this bug were, so I waited a couple days to see how the discussion went before posting here. Giorgio has now provided an illustration of his security concerns regarding this bug, and I feel a heads-up on this thread is warranted now. BTW, he's built a workaround into later versions of NoScript.

Last edited by win32sux; 06-17-2008 at 02:04 PM.
 
Old 06-18-2008, 12:13 PM   #93
shawnbishop
Member
 
Registered: Dec 2005
Location: South Africa
Distribution: CentOS,Ubuntu,Fedora
Posts: 249

Rep: Reputation: 30
Download Firefox 3 today!!!, its avaliable
 
Old 06-18-2008, 12:58 PM   #94
Cuetzpallin
Member
 
Registered: Feb 2008
Location: Monterrey, MX
Distribution: Slackware since 3.4 and love it!!!
Posts: 162

Rep: Reputation: 31
Quote:
Originally Posted by shawnbishop View Post
Download Firefox 3 today!!!, its avaliable
Since yesterday on all my boxes
 
Old 06-19-2008, 01:17 PM   #95
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Exclamation Mozilla Firefox Unspecified Code Execution Vulnerability

Quote:
Description:
A vulnerability has been reported in Mozilla Firefox, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an unspecified error and can be exploited to execute arbitrary code e.g. when a user visits a specially crafted web page.

The vulnerability is reported in versions 3.0 and 2.0.x. Other versions may also be affected.

Solution:
Do not follow untrusted links nor browse untrusted web sites.
Secunia Advisory
 
Old 06-19-2008, 09:36 PM   #96
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
FYI, it's starting to sound like the above vulnerability might just be the tip of the iceberg.
 
Old 06-23-2008, 03:43 PM   #97
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Ran into this interesting extension vulnerability claim (with proof-of-concept) on BugTraq.

Last edited by win32sux; 06-23-2008 at 03:53 PM.
 
Old 07-02-2008, 05:28 PM   #98
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Mozilla Firefox Multiple Vulnerabilities

Quote:
Description:
Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, bypass certain security restrictions, disclose sensitive information, or potentially compromise a user's system.

1) Multiple errors in the layout and JavaScript engines can be exploited to corrupt memory.

2) An error in the handling of unprivileged XUL documents can be exploited to load Chrome scripts from a "fastload" file via "<script>" elements.

3) An error in the "mozIJSSubScriptLoader.LoadScript()" function can be exploited to bypass XPCNativeWrappers and run arbitrary code with Chrome privileges.

Successful exploitation requires that an add-on using the affected function is installed.

4) An error in the block reflow process can be exploited to cause a crash or potentially execute arbitrary code.

5) An error in the processing of file URLs contained within local directory listings can potentially be exploited to execute malicious JavaScript content.

6) Multiple errors in the implementation of the JavaScript same origin policy can be exploited to execute arbitrary script code in the context of a different domain.

7) Multiple errors in the verification of signed JAR files can be exploited to execute arbitrary JavaScript code with the privileges of the JAR's signer.

8) An error in the implementation of file upload forms can be exploited to upload arbitrary local files to a remote webserver via specially crafted "DOM Range" and "originalTarget" elements.

9) An error in the Java LiveConnect implementation on Mac OS X can be exploited to establish arbitrary socket connections.

10) An uninitialized memory access in the processing of improperly encoded ".properties" files can potentially be exploited to disclose sensitive memory via an add-on using the malformed file.

11) An error in the processing of "Alt Names" provided by "peer" trusted certificates can be exploited to conduct spoofing attacks.

12) An error in the processing of Windows URL shortcuts can be exploited to run a remote site as a local file.

Successful exploitation requires that the user is tricked into downloading and then opening a malicious Windows URL shortcut.

The vulnerabilities are reported in versions prior to 2.0.0.15.

[...]

Solution:
Update to version 2.0.0.15.
http://www.mozilla.com/en-US/firefox/all-older.html
Secunia Advisory
 
Old 07-05-2008, 09:16 AM   #99
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Mozilla Firefox Malformed JPEG File Denial of Service Vulnerability

I can't seem to get the proof-of-concept to download, so I haven't been able to confirm this.
Quote:
Mozilla Firefox is prone to a remote denial-of-service vulnerability.

Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions.

This issue affects Mozilla FireFox 3 running on Ubuntu Linux 8.04; other versions running on different platforms may also be affected.
Bugtraq ID: 29984

Last edited by win32sux; 07-05-2008 at 09:34 AM.
 
Old 07-08-2008, 06:22 AM   #100
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Mozilla Security Metrics Project

Quote:
Mozilla has been working with security researcher and analyst Rich Mogull for a few months now on a project to develop a metrics model to measure the relative security of Firefox over time. We are trying to develop a model that goes beyond simple bug counts and more accurately reflects both the effectiveness of secure development efforts, and the relative risk to users over time. Our goal in this first phase of the project is to build a baseline model we can evolve over time as we learn what works, and what does not. We do not think any model can define an absolute level of security, so we decided to take the approach of tracking metrics over time so we can track relative improvements (or declines), and identify any problem spots. This information will support the development of Mozilla projects including future versions of Firefox.
Complete Article
 
Old 07-16-2008, 02:39 PM   #101
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Mozilla Firefox 3 URI Launching and XUL Error Page Vulnerabilities

Quote:
Description:
Some vulnerabilities have been reported in Firefox 3, which can be exploited by malicious people to bypass certain security restrictions, potentially conduct spoofing attacks, or compromise a user's system.

1) A vulnerability can be exploited to launch e.g. "file" or "chrome:" URIs in Firefox.

[...]

2) Input passed to XUL based error pages is not properly sanitised before being returned to a user and can be exploited to e.g. conduct spoofing attacks.

In combination with vulnerability #1 this can be exploited to inject arbitrary script code and execute arbitrary code in "chrome" context, but requires that a specially crafted URI is passed to Firefox and that Firefox is not running.

The vulnerabilities are reported in versions prior to 3.0.1.

[...]

Solution:
Update to version 3.0.1.
http://www.mozilla.com/en-US/firefox/
Secunia Advisory

A similar issue seems to affect Firefox 2.


EDIT: List of vulnerabilities fixed is also available directly from Mozilla for 3.0.1 and 2.0.0.16.

Last edited by win32sux; 07-17-2008 at 02:00 PM.
 
Old 08-07-2008, 05:47 PM   #102
DeepSeaNautilus
Member
 
Registered: Jul 2008
Posts: 65

Rep: Reputation: 15
How safe is firefox 3.0?

Hello I would like to know how many of the vulnerabilities you mentioned before about firefox are present in firefox 3.0 so IŽll know what to fix. Thanks
 
Old 08-07-2008, 06:28 PM   #103
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Quote:
Originally Posted by DeepSeaNautilus View Post
Hello I would like to know how many of the vulnerabilities you mentioned before about firefox are present in firefox 3.0 so IŽll know what to fix. Thanks
You can get a decent idea of which Mozilla Firefox 3.x known vulnerabilities are unpatched here.
 
Old 08-07-2008, 06:30 PM   #104
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Mozilla ups ante on security

Quote:
LAS VEGAS -- Open-source software maker Mozilla announced this week that the company will require developers to undergo training in secure programming and allow the security community to review its assessments of threats to the Firefox browser.
Full Story
 
Old 09-24-2008, 05:27 AM   #105
win32sux
Moderator
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,847

Original Poster
Rep: Reputation: 348Reputation: 348Reputation: 348Reputation: 348
Firefox 3.0.2 is out. It fixes some security issues.

The relevant Secunia advisory is here.

Last edited by win32sux; 09-24-2008 at 05:28 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Mozilla Thunderbird to Find New Home as Mozilla Foundation Focuses on Mozilla Firefox LXer Syndicated Linux News 0 07-27-2007 10:16 AM
LXer: Mozilla Firefox 1.5.0.8 and Mozilla Thunderbird 1.5.0.8 Released LXer Syndicated Linux News 0 11-09-2006 06:21 PM
LXer: Mozilla Corporation Signs Mozilla Firefox Distribution Deal with RealNetworks LXer Syndicated Linux News 0 08-03-2006 04:21 PM
LXer: Mozilla Firefox and Mozilla Thunderbird 1.5.0.5 Community Test Day LXer Syndicated Linux News 0 07-14-2006 09:54 AM
Mozilla flaws could allow attacks, data access into Firefox & Mozilla web browsers! t3gah Linux - Security 6 04-09-2006 05:00 AM


All times are GMT -5. The time now is 12:44 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration