Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
 |
GNU/Linux Basic Guide
This 255-page guide will provide you with the keys to understand the philosophy of free software, teach you how to use and handle it, and give you the tools required to move easily in the world of GNU/Linux. Many users and administrators will be taking their first steps with this GNU/Linux Basic guide and it will show you how to approach and solve the problems you encounter.
Click Here to receive this Complete Guide absolutely free. |
|
 |
09-21-2005, 12:17 AM
|
#1
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
|
Mozilla Linux Command Line URL Parsing Security Flaw Reported
Quote:
|
A critical input validation security vulnerability affecting Linux versions of Mozilla Firefox and the Mozilla Application Suite has been reported today. The flaw could allow an attacker to execute arbitrary commands on a victim's system. The bug exists in the Linux shell scripts that Firefox and the Mozilla Application Suite rely on to parse URLs supplied on the command line or by external programs. If the supplied URL contains any Linux commands enclosed in backticks, these will be executed before Firefox or the Mozilla Application Suite tries to open the URL. Variables such as $HOME will also be expanded.
|
Complete Article
This bug has been classified as Extremely Critical by Secunia:
http://secunia.com/advisories/16869/
BTW, from the mozillaZine article:
Quote:
|
A solution to this flaw has been developed and will be included in the forthcoming Firefox 1.0.7 and Mozilla 1.7.12 releases.
|
Last edited by win32sux; 09-21-2005 at 01:11 AM.
|
|
|
|
09-21-2005, 09:07 AM
|
#2
|
|
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Rep:
|
Thanks for the info on this. I'll sticky it for awhile.
|
|
|
|
09-22-2005, 02:27 PM
|
#3
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
Original Poster
|
Quote:
|
Mozilla Firefox 1.0.7, a security and stability update to the flagship Mozilla browser, is now available for download. Fixes are included for the international domain name (IDN) link buffer overflow vulnerability and the Linux command line URL parsing flaw. There are also other security and stability changes, including a fix for a crash experienced when using certain Proxy Auto-Config scripts. In addition, some regressions introduced by previous 1.0.x security updates have been resolved.
|
Complete Article | Release Notes
Quote:
|
Mozilla 1.7.12, a security and stability update to the Mozilla Application Suite, is now available for download. Fixes are included for the international domain name (IDN) link buffer overflow vulnerability and the Linux command line URL parsing flaw. There are also other security and stability changes, including a fix for a crash experienced when using certain Proxy Auto-Config scripts. In addition, some regressions introduced by previous 1.7.x security updates have been resolved. If this description sounds like our article on Mozilla Firefox 1.0.7, that's because most of the fixes included in the two releases are the same.
|
Complete Article | Release Notes
Last edited by win32sux; 09-23-2005 at 10:43 PM.
|
|
|
|
09-23-2005, 06:56 AM
|
#4
|
|
Member
Registered: Sep 2003
Location: Delaware, USA
Distribution: Ubuntu 12.04 LTS
Posts: 55
Rep:
|
I have read on secunia.com that Thunderbird has the same flaw. mozilla.org says that a workaround is "Do not click on links in spam or other mail from people you don't know. " and "Do not use the affected programs as the default handler for URLs. "
Later
Bob W.
|
|
|
|
09-23-2005, 10:40 PM
|
#5
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
Original Poster
|
you are correct, rjw1678... personally, i do find it a little odd that a thunderbird 1.0.7 wasn't released parallel to firefox 1.0.7, but i'm sure there's a rational explanation...
Last edited by win32sux; 09-24-2005 at 12:44 AM.
|
|
|
|
09-29-2005, 04:28 AM
|
#6
|
|
Member
Registered: Aug 2004
Location: Albany, Western Australia
Distribution: Mageia 2, SME Server 8
Posts: 610
Rep:
|
|
|
|
|
09-29-2005, 12:24 PM
|
#7
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
Original Poster
|
yes, notice how they mention firefox, thunderbird, and mozilla as affected products:
Quote:
|
Products: Firefox, Thunderbird, Mozilla Suite
|
yet for "fixed in" thunderbird isn't mentioned:
Quote:
Fixed in: Firefox 1.0.7
Mozilla Suite 1.7.12
|
and of course if you go into secunia.com you will see on the front page the extremely critical advisory for thunderbird, as it's still listed as unpatched at the time of this post:
http://secunia.com/advisories/16901/
|
|
|
|
09-30-2005, 06:47 AM
|
#8
|
|
Member
Registered: Sep 2003
Location: Delaware, USA
Distribution: Ubuntu 12.04 LTS
Posts: 55
Rep:
|
Thunderbird 1.0.7 is available.
Later
Bob W
|
|
|
|
09-30-2005, 12:51 PM
|
#9
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
Original Poster
|
Quote:
Originally posted by rjw1678
Thunderbird 1.0.7 is available.
|
thanks for the good news!!!
here's a link to the release notes for thunderbird 1.0.7:
http://www.mozilla.org/products/thun...ase-notes.html
|
|
|
|
10-06-2005, 06:39 AM
|
#10
|
|
Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
Original Poster
|
FYI, a non-critical DoS vulnerability has been found in firefox 1.0.7:
http://secunia.com/advisories/17071/
|
|
|
|
| Thread Tools |
Search this Thread |
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 01:09 PM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|