Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Firefox Develops Security Holes
Techtree.com ^ | May 09, 2005 | Techtree News Staff

Posted on 05/09/2005 7:00:15 AM PDT by holymoly

Firefox seems to be heading Internet Explorer's way with security research company Secunia stating on its website that two vulnerabilities found in the popular browser can be exploited to conduct cross-site scripting attacks and compromise a user's system.

The Mozilla Foundation is aware of the two potentially critical Firefox security vulnerabilities. They maintain that there are currently no known active exploits of these vulnerabilities though a "proof of concept" has been reported.

Mozilla stated that it is aggressively working to provide a more comprehensive solution to these potential vulnerabilities and will provide that solution in a forthcoming security update. Users can further protect themselves by temporarily disabling JavaScript.

According to Secunia the problem is that "IFRAME" JavaScript URLs are not properly protected from being executed in context of another URL in the history list. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site.

It seems that input passed to the "IconURL" parameter in "InstallTrigger.install" is not properly verified before being used. This can be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL.

A combination of the vulnerabilities can be exploited to execute arbitrary code.

Secunia also claims that the exploit code is publicly available. So far the vulnerabilities have been confirmed in version 1.0.3. Other versions may also be affected.

A temporary solution has been added to the sites "update.mozilla.org" and "addons.mozilla.org" where requests are redirected to "do-not-add.mozilla.org". This will stop the publicly available exploit code using a combination of the vulnerabilities to execute arbitrary code in the default settings of Firefox.


TOPICS: News/Current Events; Technical
KEYWORDS: browser; bug; firefox; flaw; mozilla; security
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-72 next last
To: frogjerk
IE - Of 80 total vulnerabilities - 14% Extremely Critical, 28% Highly Critical
Firefox - Of 16 total vulnerabilities - 6% Extremely Critical , 13% Highly Critical
The numbers speak for themselves...

Actually they do -- thanks for pointing that out. You neglected TIME (length of each app on the market, and time taken to isolate and fix the vulnerabilities.) The numbers says that 80 vulnerabilities in Explorer and only 16 have been fixed in Firefox. This pops the myth "that open source is more secure" because Firefox has been around a lot less then Explorer and still major vulnerabilities have been found. It would be an interesting data point to discover how many vulnerabilities Explorer had in the same time period as Firefox.

41 posted on 05/11/2005 9:10:41 AM PDT by MrsEmmaPeel
[ Post Reply | Private Reply | To 20 | View Replies]

To: MrsEmmaPeel
Actually they do -- thanks for pointing that out. You neglected TIME (length of each app on the market, and time taken to isolate and fix the vulnerabilities.) The numbers says that 80 vulnerabilities in Explorer and only 16 have been fixed in Firefox. This pops the myth "that open source is more secure" because Firefox has been around a lot less then Explorer and still major vulnerabilities have been found. It would be an interesting data point to discover how many vulnerabilities Explorer had in the same time period as Firefox.

I believe Firefox is based on the Mozilla/Netscape code and has been around for quite a while...

42 posted on 05/11/2005 9:28:06 AM PDT by frogjerk
[ Post Reply | Private Reply | To 41 | View Replies]

To: frogjerk
I believe Firefox is based on the Mozilla/Netscape code and has been around for quite a while...

Given that Firefox has as many as 20% of the vulnerabilities of IE in its short term of existence, that doesn't speak well to Firefox's future security liability...
43 posted on 05/11/2005 9:56:48 AM PDT by Bush2000
[ Post Reply | Private Reply | To 42 | View Replies]

To: Shadow Deamon

I recently downloaded Firefox and now find that if I close it I cannot reopen it without rebooting. Does anyone else have this problem with Firefox? Am I doing something wrong?


44 posted on 05/11/2005 10:06:51 AM PDT by patj
[ Post Reply | Private Reply | To 21 | View Replies]

To: Bush2000
Ditto. So where's the downside for me?

Sorry, I misunderstood. I thought you were using antivirus, anti-spyware, multiple firewalls, and on the multiple OS, app upgrades... etc. train.

these series of patches are just your imagination.

Sorry again. I didn't mean to imply that absolutely nothing was required after buying the 'puter - only that an almost hassle-free secure computing environment exists today.

45 posted on 05/11/2005 10:41:16 AM PDT by D-fendr
[ Post Reply | Private Reply | To 39 | View Replies]

To: Bush2000
When you compare what we had just a few short years ago, the differences in terms of price and quality are enormous. And they're getting better.

Good to hear you say. I think the same will be true for security eventually. It may be the major software vendors or it may be with extending the security fence by ISPs or some combination. But I don't think the current security cost/vulnerability situation will continue indefinitely.

46 posted on 05/11/2005 10:44:00 AM PDT by D-fendr
[ Post Reply | Private Reply | To 40 | View Replies]

To: Bush2000
Given that Firefox has as many as 20% of the vulnerabilities of IE in its short term of existence, that doesn't speak well to Firefox's future security liability...

I fail to see the downside of using Firefox right now...If you are stating that it will be as insecure as the product that most users are using right now (IE), that does little to champion IE usage.

IE users:"Don't worry, Firfox will be as bad as us soon. So, use IE now and despair with us."

47 posted on 05/11/2005 11:01:43 AM PDT by frogjerk
[ Post Reply | Private Reply | To 43 | View Replies]

To: patj

Which version are you using?


48 posted on 05/11/2005 11:03:53 AM PDT by frogjerk
[ Post Reply | Private Reply | To 44 | View Replies]

To: patj

That's odd. It sounds like the process isn't terminating properly for some reason. The first thing I would suggest is disabling any extensions you've added and returning to the default skin if you've changed it. If that solves the problem, you can re-enable the extensions one at a time until you find the offender. If that doesn't fix it, or you don't have any extensions/skins in the first place, I would suggest uninstalling it and reinstalling it.


49 posted on 05/11/2005 11:06:04 AM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 44 | View Replies]

To: D-fendr
Sorry, I misunderstood. I thought you were using antivirus, anti-spyware, multiple firewalls, and on the multiple OS, app upgrades... etc. train.

I do have wireless AP which also serves as a hardware firewall. My machine is setup to take automatic updates, and my virus and spyware scanners also update every day at 2am. There's really no practical maintenance for me. I know that must disappoint some people. But them's the facts.
50 posted on 05/11/2005 2:10:22 PM PDT by Bush2000
[ Post Reply | Private Reply | To 45 | View Replies]

To: D-fendr
Sorry again. I didn't mean to imply that absolutely nothing was required after buying the 'puter - only that an almost hassle-free secure computing environment exists today.

Again, what's the downside to using IE for me? I don't need to maintain it. I don't have any spyware on my box at all. It can't get any easier.
51 posted on 05/11/2005 2:11:40 PM PDT by Bush2000
[ Post Reply | Private Reply | To 45 | View Replies]

To: D-fendr
Good to hear you say. I think the same will be true for security eventually. It may be the major software vendors or it may be with extending the security fence by ISPs or some combination. But I don't think the current security cost/vulnerability situation will continue indefinitely.

According to the press reports, Longhorn will have a big emphasis on security: restricted accounts by default, sandboxed IE, etc. Should be interesting...
52 posted on 05/11/2005 2:13:06 PM PDT by Bush2000
[ Post Reply | Private Reply | To 46 | View Replies]

To: frogjerk
I fail to see the downside of using Firefox right now...If you are stating that it will be as insecure as the product that most users are using right now (IE), that does little to champion IE usage.

Firefox already is as bad as IE. You simply don't know it.
53 posted on 05/11/2005 2:13:46 PM PDT by Bush2000
[ Post Reply | Private Reply | To 47 | View Replies]

To: Bush2000
Again, what's the downside to using IE for me? I don't need to maintain it. I don't have any spyware on my box at all. It can't get any easier.

It's more the Windows overhead that could be little easier anyway: no antivirus or spysweepers to buy, install or manage, or worry about conflicts, or setting up a secure Windows install, and then those occassions where you have to reinstall..

But, I think you probably have your stuff pretty tight and down to an efficient maintenance schedule. It's more the average Joe, Jane or Grandma Sue user who sucks wind on security.

Then there's the business user - usually an exec or laptop user - who seems to find a way to get infected every month or two. There's quite a bit of overhead in corp technology spent on keeping it as productive as it is, still stuff gets through and even if it doesn't that's money that could be spent on better things..

54 posted on 05/11/2005 3:29:06 PM PDT by D-fendr
[ Post Reply | Private Reply | To 51 | View Replies]

To: Bush2000
restricted accounts by default

I don't get why this wasn't the way before. Why not turn on vulnerabilities instead of having to know all the doors to close?

sandboxed IE

Help me out a bit on this one. My (quite limited) understanding is that IE is the GUI or a required dll for the GUI, and that this one of the main reasons IE exploits have such damaging capability.

Anywhere near correct?

55 posted on 05/11/2005 3:35:07 PM PDT by D-fendr
[ Post Reply | Private Reply | To 52 | View Replies]

To: Bush2000
Firefox already is as bad as IE. You simply don't know it.

Prove it.

56 posted on 05/11/2005 3:54:25 PM PDT by frogjerk
[ Post Reply | Private Reply | To 53 | View Replies]

To: frogjerk

The recent vulnerability rate is just as bad as IE's.


57 posted on 05/12/2005 12:42:43 AM PDT by Bush2000
[ Post Reply | Private Reply | To 56 | View Replies]

To: D-fendr
It's more the Windows overhead that could be little easier anyway: no antivirus or spysweepers to buy, install or manage, or worry about conflicts, or setting up a secure Windows install, and then those occassions where you have to reinstall..

I didn't pay for any of this software. It's all free. Similarly, I installed it once. No maintenance involved. It updates and runs in the middle of the night, when I'm not using the machine. So where's the downside for me?

But, I think you probably have your stuff pretty tight and down to an efficient maintenance schedule. It's more the average Joe, Jane or Grandma Sue user who sucks wind on security.

The average Joe should check out the Microsoft Anti-Spyware Beta, SpyBot Search & Destroy, and LavaSoft Ad-Aware SE Personal Edition. All free. The MS tool is completely automated.

Then there's the business user - usually an exec or laptop user - who seems to find a way to get infected every month or two. There's quite a bit of overhead in corp technology spent on keeping it as productive as it is, still stuff gets through and even if it doesn't that's money that could be spent on better things..

There's literally no distinction between these sets of users, given the sophistication of the available tools.
58 posted on 05/12/2005 12:47:44 AM PDT by Bush2000
[ Post Reply | Private Reply | To 54 | View Replies]

To: D-fendr
I don't get why this wasn't the way before. Why not turn on vulnerabilities instead of having to know all the doors to close?

Well, actually, Windows does support restricted accounts already. The difference is that MS will actually enforce the use of restricted accounts for users with OEMs.

Help me out a bit on this one. My (quite limited) understanding is that IE is the GUI or a required dll for the GUI, and that this one of the main reasons IE exploits have such damaging capability. Anywhere near correct?

IE is just an application. Sure, it's integrated into the OS. But the fact of the matter is that it's essentially just an app. From what the press reports say, MS will make IE run with reduced privileges, even if you happen to be logged in as Administrator (aka root). So, even if exploits occur, buffer overflows, hijacking the registry, and other kinds of attacks will not work due to restricted privileges.
59 posted on 05/12/2005 12:51:58 AM PDT by Bush2000
[ Post Reply | Private Reply | To 55 | View Replies]

To: All
Firefox 1.0.4 is available at www.mozilla.org if you all haven't gotten it yet.

I just downloaded Firefox yesterday to update an infrequently used laptop (and it was 1.0.3 at the time) so this must have gone up recently.

60 posted on 05/12/2005 12:53:25 AM PDT by monkapotamus
[ Post Reply | Private Reply | To 58 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-72 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson