• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Firefox Update

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

dicecca112

Member
Joined
Feb 25, 2004
Location
MA, USA
The Mozilla Foundation has released a workaround for a critical buffer overflow vulnerability in the Firefox browser that was first made public last Friday.
ADVERTISEMENT

By Friday afternoon, Mozilla developers had posted a software patch and instructions for a workaround, both of which disable the buggy Firefox feature.
Open to Attack

The vulnerability, which was reported by security researcher Tom Ferris to the Mozilla team earlier this week, concerns the International Domain Name (IDN) feature that Mozilla products use to process Web pages that do not use Latin alphabet characters in their names.

Links pointing to a host with a long name composed entirely of dashes can be crafted so that Firefox will execute arbitrary code of an attacker's choosing, meaning that an attacker theoretically could use the flaw to take control of a user's machine.

No code that actually exploits this vulnerability has yet been seen, but all versions of Mozilla Firefox and the Mozilla Suite are affected, according to the Mozilla team. The vulnerability even includes version 1.5 Beta 1 (Deer Park Alpha 2), which was released on Thursday.

"It's something we take seriously because it could be used for bad things," said Mike Schroepfer, director of engineering with the Mozilla Foundation.
Solid Fix Pending

Because both the patch and the workaround simply disable IDN, users who require the feature to visit international Web sites should stick to visiting Web sites they know and trust until the problem is actually repaired in the browser, Schroepfer said.

When that will happen remains unknown. "We're determining that now," he said.

Ferris described the flaw in his Security Protocols Web site and on the Full Disclosure security mailing list last week. He said the problem is caused by a bug in the code Firefox uses to process HTML (Hypertext Markup Language) links in Web pages.

In August, Ferris reported a critical flaw in fully patched versions of Microsoft Internet Explorer 6 running on
Windows XP Service Pack 2. The flaw was acknowledged by Microsoft, but in that instance, Ferris did not reveal any details of the flaw or how it could be exploited.

Peter Sayer of the IDG News Service contributed to this report.
 
My switch from FF to opera makes me feel happier all the time! FF is still lightyears better than IE though... yet so many people are blind to that statement!
 
Back