Firefox patches address three critical vulnerabilities

By Scott M. Fulton, III | Published December 17, 2008, 1:59 PM


Download Mozilla Firefox 3.0.5 for Windows from FileForum now.

Internet Explorer is apparently not the only browser this week that's the subject of preventative measures, as Mozilla revealed this morning that the real reason for issuing Firefox 3.0.5 was to prevent a possible wave of page hijacks.

While version 3.0.5 of Mozilla's Firefox browser was, for the most part, perceived as a bug fix, security bulletins released this morning by the organization warn that the update addresses new vulnerabilities that are awaiting official classification. Two of those cases involve violations of the company's same-origin policy, in which any script being run by a site or attachment sent by a site must derive from the same DNS address as the source page that refers to it.

It's this policy that's designed to prevent hijacking of a site by a malicious impostor. This morning, Mozilla is crediting one of its most prolific bug finders through the years -- who only identifies himself/herself as moz_bug_r_a4 -- for locating the flaws.

One of these cases involves XBL binding -- a newer and more modular way for developers to associate an element on an HTML page with functionality, templates, and stylesheet instructions, based on a standard from W3C. Some of that functionality may include JavaScript; and as moz_bug_r_a4 apparently discovered, if the XBL element is bound to a page that has not yet loaded, conceivably that JavaScript could come from anywhere. In other words, the same-origin policy only appears to apply when there is a page that sets the origin; without it, the script could hail from a malicious site.

The other moz_bug_r_a4 discovery reported this morning is an apparently clever way to inject Web page addresses into the automatic session restoration feature of the browser. If a malicious user can trigger the browser to crash, session restore could pull up an unwanted page among all the others, as it tries to restore the user's previous browsing session.

The third critical vulnerability reported this morning appears to be an umbrella case for several JavaScript integrity problems, in which browser crashes could lead to the execution of leftover code in memory, without privilege. No further details are known about these problems at this time.

This week's slate of bug fixes also triggered one more release of the venerable Firefox 2 series browser -- this time, version 2.0.0.19. The organization had made indications earlier that version 2.0.0.18 -- which removed a phishing filter feature that ended up being incompatible with Google's current list standards -- would be the last in that series.

Download Mozilla Firefox 3.0.5 for Linux from FileForum now.

Comments

View comments by with a score of at least

oh noes! say it isn't so!

Score: 0

|

The link at the bottom links to the linux version. Cute.

Score: 0

|

What gave it away? The fact that it says "Download Mozilla Firefox 3.0.5 for Linux from FileForum now"?

Score: 0

|

Did you notice the link at the top?

Score: 0

|

If you use Firefox, just go get it.
Thanks BN for the info.
Simple.

Gee, no worrying about what XXX is doing, and if they are smart, they won't care about what FF is doing - other than to get the updates if they apply.

Score: 0

|

Report: Microsoft to randomize Europe's browser screen choices

The fact that "A" is for "Apple" was apparently at the heart of browser vendor objections to Microsoft's alternative to listing IE first.

Acer eclipses Dell for #2 spot in global PC shipments, says iSuppli data

It literally does look like a 360-degree turnaround in Dell's fortunes, as the bells of bad tidings now toll solely for Dell.

Microsoft, don't hang up on Windows Mobile, but do call for help

Only a Manhattan Project can save Microsoft's phone strategy now.

See ya later, WinMo: Microsoft's mobile strategy needs a reboot

Carmi Levy | Wide Angle Zoom: Hands up if you're considering upgrading to a Windows phone for the holidays...Anybody?

Playing catch-up in 2010: Windows Mobile, BlackBerry, and Symbian

Microsoft, RIM, and Nokia are each working on improved mobile operating systems. But could these efforts add up to too little, too late?

Will Nokia's plans further alienate American consumers?

A look at Nokia's plans for the coming years does little to shine up the company's increasingly dull image.

Bing bonked by service outage Thursday, Microsoft configured the wrong server

It's always nice to have a backup, but it's even nicer to remember which one is the backup. That's the lesson Bing's admins learned yesterday evening.

Survey reveals there are more women then men, including on social networks

If you think you can market your products and services online as though you're selling car batteries in the middle of halftime, think again. And again.

Android team updates 'Donut' and 'Eclair' SDKs

The Android SDK includes components which optimize app development for each version of the mobile operating system. Today, the 1.6 and 2.0 components got updates.

The Black Screen Syndrome, or, Tech news in search of the apocalypse

Scott Fulton On Point: This is a story about something that should not have been a story, about something that at one time was a story.

Online advertising evolves away from display, toward interactive software

Marketing departments and agencies are increasingly establishing positions for "creative technologists" who can steer designers and developers toward platforms that enable direct connections with consumers.