Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Exploit turns up heat for Firefox flaw
CNet News ^ | 8 February 2006 | Joris Evers

Posted on 02/09/2006 9:50:40 AM PST by ShadowAce

Computer code that could be used in cyberattacks on Firefox users has been released, increasing the urgency for people to upgrade to the latest version of the Web browser.

The two pieces of exploit code, posted online earlier this week, take advantage of a security vulnerability in Firefox that Mozilla patched in an update Thursday. In response to the exploit release, the browser maker on Tuesday upgraded the severity rating of the flaw from "moderate" to "critical," its most serious rating.

"This exploit was published after we released the 1.5.0.1 update," said Mike Schroepfer, vice president of engineering at Mozilla. "Most of our users had already been upgraded by the time this exploit was published."

The code could be used to commandeer computers running a vulnerable version of the open-source Web browser on Linux or Mac OS X systems. It has been published as part of the Metasploit Framework, a widely used hacking tool.

The specific flaw exists only in Firefox 1.5 and was fixed in Firefox 1.5.0.1. The problem could cause a memory corruption an outsider could use to run code on a vulnerable PC, according to a Mozilla advisory. The corruption would come from calling the "QueryInterface" method of the Location and Navigator objects in the browser.

Firefox users have already been urged to install the patched version of the browser. Security monitoring company Secunia last week rated the Firefox update "highly critical," and Mozilla has pushed out updates.

If for some reason users have not upgraded, they should definitely do so, Schroepfer said.


TOPICS: Technical
KEYWORDS: exploits; firefox; patch
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-82 next last
"This exploit was published after we released the 1.5.0.1 update," said Mike Schroepfer, vice president of engineering at Mozilla.
1 posted on 02/09/2006 9:50:43 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

2 posted on 02/09/2006 9:50:55 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

This is impossible because we know that open source code is invincible. We've been told. By "They".


3 posted on 02/09/2006 9:56:09 AM PST by Uncle Miltie (Muhammed "consummated that marriage when she (Aisha) was nine years old." Bukhari vol.5:236 p.153.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Wonder if ver 1.0.7 is at risk?


4 posted on 02/09/2006 9:58:11 AM PST by TexasTransplant (NEMO ME IMPUNE LACESSET)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Brad Cloven
This is impossible because we know that open source code is invincible.

I keep hearing that.

< Inigo Montoya >I do not think it means what you think it means.< /Inigo Montoya >

5 posted on 02/09/2006 9:59:36 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 3 | View Replies]

To: TexasTransplant
The specific flaw exists only in Firefox 1.5 and was fixed in Firefox 1.5.0.1
6 posted on 02/09/2006 9:59:53 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 4 | View Replies]

To: TexasTransplant
Wonder if ver 1.0.7 is at risk?

I believe it is. I'd recommend going to 1.5.0.1

7 posted on 02/09/2006 10:00:10 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 4 | View Replies]

To: N3WBI3; TexasTransplant
The specific flaw exists only in Firefox 1.5...

Arrgh! I missed that. Sorry

8 posted on 02/09/2006 10:01:01 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce
"This exploit was published after we released the 1.5.0.1 update,"

Good for them. Patch before exploits are released. Microsoft can learn from this.

9 posted on 02/09/2006 10:04:29 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
No problem.

Firefox automatically notified me as soon as the update was available.. ( Thursday )
My browser was updated less than 5 minutes later..

10 posted on 02/09/2006 10:04:33 AM PST by Drammach (In the kingdom of the blind, the one-eyed man is king..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

I was wondering why fc3 is still rinning 1.0.7 until I read this article...


11 posted on 02/09/2006 10:04:35 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 8 | View Replies]

To: TexasTransplant

Probably is, but why keep using 1.0.7?


12 posted on 02/09/2006 10:05:53 AM PST by Terpfen (72-25: The Democrats mounted a failibuster!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: N3WBI3

When I try to download it the dialoge box says it must go to a disc and I cannot change it. Is there a way to download it directly? Thanks


13 posted on 02/09/2006 10:07:18 AM PST by learner
[ Post Reply | Private Reply | To 11 | View Replies]

To: Terpfen

Some of us just want to use the one (RPM) that came with our distro to centralize the update service..


14 posted on 02/09/2006 10:09:10 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 12 | View Replies]

To: learner

What OS are you patching it on?


15 posted on 02/09/2006 10:09:30 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ShadowAce

For all those complaining about IE and Microsoft flaws...It just goes to show that ANYTING can be exploited....it's just a matter of time and popularity.


16 posted on 02/09/2006 10:11:01 AM PST by rightwingextremist1776
[ Post Reply | Private Reply | To 1 | View Replies]

To: CedarDave

FYI


17 posted on 02/09/2006 10:12:17 AM PST by Primetimedonna (Charter member of the San Francisco SnowFlakes! We love our Tony! It's SAN FRANCISCO, not Frisco.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: N3WBI3

Windows XP


18 posted on 02/09/2006 10:13:59 AM PST by learner
[ Post Reply | Private Reply | To 15 | View Replies]

To: rightwingextremist1776
Except that nobody ever said that OSS software is immune to flaws, thats just something people say they hear when they want to bring a red herring to the discussion.

But I have heard people say that the architecture of a program does not matter *ONLY* its popularity and that is flat out wrong.

19 posted on 02/09/2006 10:16:46 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 16 | View Replies]

To: learner

Well Im using Linux (Fedora) right now so I cant try the update but Ill see if I get time tomorrow..


20 posted on 02/09/2006 10:17:24 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-82 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson