Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » Mozilla Closes Down Critical Security Holes  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Mozilla Closes Down Critical Security Holes

The Mozilla Foundation has just released Firefox version 2.0.0.10 which resolves three critical vulnerabilities – but new issues have already reared their ugly heads.

One of the most serious vulnerabilities concerned handling of .jar files. An error in the Jar protocol implementation allowed cross-site scripting attacks on filters and other safeguards to grab login information and other data. Another scenario describes attacks with carefully crafted archives. Redirects allowed attackers to exploit the vulnerability. The second error to have been removed was exploitable by setting the "window.location" to redirect HTTP headers and thus launch cross-site scripting attacks.

The third error originated from a memory management bug which attackers could exploit to crash the browser or execute malicious code on the victim’s system. These vulnerabilities also affect Mozilla Seamonkey, a new version of which (1.1.7) will become available in the next few days.

But shortly after version 2.0.0.10 of Firefox was released, the next crop of bugs was identified. US-based developer Kevin Han has reported a bug that prevents the browser from displaying graphics embedded using Javascript. The new version responds to the "canvas.drawImage()" instruction with an error message of "NS_ERROR_NOT_AVAILABLE"; instead of displaying vector graphics, the method now draws pixel images in them.

Despite the new bug, the Firefox developers still advise users to update to the new version of the browser. The Mozilla Foundation servers have versions in various languages with distribution packages due to follow in the next few days.

(Jan Rähm)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Firefox 2.0.0.9 Corrects Latest Release
Security Bug in Konqueror, Updates for Seamonkey & Co
FOSDEM: Fennec Beta Scheduled for End of February
Bespin 0.1: Mozilla's Collaborative Web Code Editor
From 3.1 to 3.5: Version leap for Firefox?
Insecure Candidates: Chrome Wins Hacking Contest
Live Streaming from ApacheCon Europe 2009

All about Apache in 19 talks

Watch 3 days full of Apache talks live from Amsterdam on March 25-27 in the convenience of your home or office. Topics are: Apache Hadoop, Tomcat for Developers and Administrators, HTTP Server Administration and much more.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]