Firefox security issue, fix slated for next week

Started by Gary, Mar 26, 2009, 07:26:16

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Gary

"Online attack code has been released targeting a critical, unpatched flaw in the Firefox browser.

The attack code, written by security researcher Guido Landi was published on several security sites Wednesday, sending Firefox developers scrambling to patch the issue. Until the flaw is patched, this code could be modified by attackers and used to sneak unauthorized software onto a Firefox user's machine. By tricking a victim into viewing a maliciously coded XML file, an attacker could use this bug to install unauthorized software on a victim's system"


Just a warning to all us FF users to beware, till 3.08 is released next week, as there seems to be no way of reducing the attack vector at this time, at least it will get patched quickly.
Damned, if you do damned if you don't

Rik

Thanks, Gary. So, that's us all off line for a week then? ;D
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Quote from: Rik on Mar 26, 2009, 08:57:42
Thanks, Gary. So, that's us all off line for a week then? ;D
Just duck and dive, Rik  ;D That sounds like a dance......
Damned, if you do damned if you don't

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Damned, if you do damned if you don't

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Steve

Steve
------------
This post reflects my own views, opinions and experience, not those of IDNet.

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Steve

My wife would not approve and I'd get the ugly one.
Steve
------------
This post reflects my own views, opinions and experience, not those of IDNet.

somanyholes

for those that want to look further. The link below does not exploit the system...

http://www.milw0rm.com/exploits/8285


and yes the file you can download happily crashed my ff




Rik

Quote from: stevethegas on Mar 26, 2009, 09:10:57
My wife would not approve and I'd get the ugly one.

Someone who wasn't into hi fi in the 60s. ;D
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

Quote from: somanyholes on Mar 26, 2009, 09:13:26
for those that want to look further. The link below does not exploit the system...

http://www.milw0rm.com/exploits/8285


and yes the file you can download happily crashed my ff






I just get:

// firefox XSL parsing remote memory corruption poc

// k`sOSe - works both in windows and linux

http://milw0rm.com/sploits/2009-ffox-poc.tar.gz

# milw0rm.com [2009-03-25]
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Steve

If you uncompress it and then open the file ff crashes.
Steve
------------
This post reflects my own views, opinions and experience, not those of IDNet.

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Gary

Quote from: Rik on Mar 26, 2009, 09:04:15
;D

You need a more subtle approach. :)
I tried that, Rik. I said the garden gate would only take an hour, it took 2 and a half  :red:
Damned, if you do damned if you don't

Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

Sebby


somanyholes


Lance

Quote from: Sebby on Mar 26, 2009, 13:14:24
So which is the safest browser this week? ::)

The oone on a computer not switched on :)
Lance
_____

This post reflects my own views, opinions and experience, not those of IDNet.

Rik

 ;D

It's becoming increasingly true, unfortunately. :(
Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.


somanyholes

it's an old school text based browser sebby, that isn't much use in the web world today. The reason it's probably fairly secure is the fact that there's pretty much no addons that you can use and get owned by. No flash, pdf's active x so on and so forth. A neat little appp for basic text stuff though.

http://www.jikos.cz/~mikulas/links/screenshots/jpg.html


Rik

Rik
--------------------

This post reflects my own views, opinions and experience, not those of IDNet.

somanyholes