Guide to the TechWeb Network


The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • |  Print this page Print this page
  • |   Bookmark and Share

Following Bevy Of Patches, The Firefox Browser Is Still Vulnerable


Posted by George Hulme, Feb 11, 2008 01:57 PM

On Friday, Feb. 8, Mozilla released an updated version of its Firefox Web browser that aimed to fix 10 vulnerabilities. Now, at least one security researcher says flaws still remain.

The flaws updated on Friday included a nasty bunch, including fixing privilege escalation, cross site scripting vulnerabilities, and remote code execution, among many others.

Then, security researcher Ronald van den Heetkamp, just hours after the release of the updated browser, version 2.0.012, posted an advisory where he detailed a proof-of-concept that explains how the browser still remains at-risk.

The flaw in question, and which was purportedly patched, exists when users have enabled any of Firefox's existing 600 add-ons. When doing so, they become vulnerable, in security jargon, to a directory transversal attack.

In English, that means attackers can take advantage of poorly constructed validation of input file names. The end result is that attackers can gain access to computer files that aren't intended to be accessible by anyone but the user.

In this case, according to van den Heetkamp's analysis, attackers could access all of a user's Firefox preferences, or open "nearly every file stored in the Mozilla programs file directory."

Not good. And this is something that Mozilla needs to rectify quickly.

More information regarding Firefox security is available here, including details on the 10 patches issued on Friday.

For the remaining flaw, van den Heetkamp recommends using a different Web browser until a fix is published, or running a Firefox extension known as NoScript, which is available here.

« Speculation About Oracle Acquisition Drives Up Salesforce.com Stock | Main | Baby Boomer 'Brain Drain' Will Be A Slow Leak »



Tomorrow's CIO: Do you have what it takes?
Find out at the 2008 InformationWeek 500 Conference
Sept. 14-16, St. Regis Resort, Monarch Beach, Calif.


Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.






  1. Google Gets Chatty, Creates New iPhone Instant Messaging Program
  2. Powerset Grab Shows Microsoft's Commitment To Search
  3. Why Are So Many People Freaking Out About The Unlocked iPhone's $700 Price Tag?
  4. Vint Cerf Says Government Needs To Encourage Internet Competition
  5. An iPhone With A Slide-Out QWERTY?


  1. Apple Drops Price Of MacBook Air
  2. Google Employees Warned Of Data Breach At Benefits Company
  3. 'Containers' Out Perform Virtualization For KV Pharmaceuticals
  4. Mobile Music A $7.3 Billion Industry By 2011
  5. IBM Develops Audio Masking Technology To Protect Call Center Recordings
  6. IBM Back On Top Of Server Market

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
  JUNE 2007
MAY 2007
APRIL 2007
MARCH 2007
FEBRUARY 2007
JANUARY 2007
DECEMBER 2006
NOVEMBER 2006