Version: 2008
  • On TechRepublic: Windows 7: Slower to boot than Vista?

April 18, 2005 8:20 AM PDT

Mozilla flaws could allow attacks, data access

  • 42 comments
Multiple vulnerabilities that could allow an attacker to install malicious code or steal personal data have been discovered in the Mozilla Suite and the Firefox open-source browser.

Details of the nine flaws were published on Mozilla's security Web site over the weekend.

Ian Latter, senior security consultant at Internet security specialist Pure Hacking, said most of the vulnerabilities are based on the way the applications handle JavaScript.

"There are some permission issues related to running JavaScript at an escalated privilege level. They remove some of the security measures used to keep JavaScript sandboxed and allow it to potentially do malicious things to your computer," Latter said.

Another issue could allow malicious scripts to gain access to random pieces of memory, he said.

"This random memory may or may not contain pieces of information about where you have been browsing. The worst-case scenario is that it could contain some personal or login information," said Latter.

On Monday, security advisory firm Secunia issued a "highly critical" rating on the flaws found in Mozilla Firefox 0.x and 1.x versions. Secunia posted its advisory on eight of the flaws.

According to the French Security Incident Response Team, attackers could run malicious code on a user's system because of a flaw in the Mozilla browser's pop-up blocker.

An advisory from the French group said, "When a pop-up is blocked, the user is given the ability to open that one pop-up...If the pop-up URL were JavaScript: selecting 'Show JavaScript:...' from the infobar or pop-up blocking status bar icon menus would run the JavaScript with elevated privileges, which could be used to install malicious software."

Another of the Firefox flaws can be exploited when a user visits a Web page that requires a plug-in that has not already been installed. The French advisory claims that if the browser's Plug-in Finder Service is used to automatically locate an appropriate plug-in, the "manual install" function can be used to "launch arbitrary code capable of stealing local data or installing malicious code."

All versions of Mozilla Suite prior to version 1.7.7 and all versions of Firefox prior to 1.0.3 are vulnerable.

Pure Hacking's Latter advises users to either disable JavaScript or download a patched version from Mozilla's Web site.

Munir Kotadia of ZDNet Australia reported from Sydney.

See more CNET content tagged:
JavaScript, flaw, Mozilla Corp., advisory, malicious code

Add a Comment (Log in or register) (42 Comments)
  • prev
  • 1
  • next
Somehow it must still be M$ fault, right?
by TheMidnightCoder April 18, 2005 9:24 AM PDT
Where are you OSS guys now...
Reply to this comment
Flaws in Open Source projects!?! AGAIN?!?
by April 18, 2005 9:55 AM PDT
THIS IS AN OUTRAGE!!!!

Whadya mean flaws were found in Mozilla Suite and FireFox? How did those wily MS guys sneak their bugs into these fine products? This can't be true. They took out an ad in the New York Times and everything. Well, at least I have *some* comfort knowing the flaws are all safely covered by the magical GPL so anyone can use them if they want to.

I demand that the EU punish Gates for this cowardly act! Maybe they can fine MS another 100 Billion dollars or something fun like that. Oh, and the folks over at News.com should be punished, too. Didn't they get the super-duper secret memo about keeping Open Source flaws quiet? Tsk. Tsk.

Now where did I put that naughty little toy penguin? He's gonna face the fury of my nerd-boy wrath for this incomprehensible act of injustice!
View reply
Right here.....
by cbiltcliffe April 18, 2005 10:44 AM PDT
>> Where are you OSS guys now...

Right here. This is a serious flaw in Mozilla products. I'll freely admit that. As serious as some holes in IE? Arguably, but not necessarily. I haven't read the descriptions of everything, but all the ones I did read required some sort of manual intervention on the part of the user, as opposed to the "I'll just install this software for you behind your back." kind of flaws that IE seems to have.

But that's rather irrelevant, really, as any flaw that can allow arbitrary code execution is bad, as far as I'm concerned.

Let's see how the flaw was handled though:

1. First bug reported to Mozilla crew on April 1st, 2005.
2. Bug discussed on Bugzilla, various suggestions and workarounds proposed.
3. Patch produced.
4. Update released on April 15th, 2005.

Total time: Two weeks plus a day for the whole process, beginning to end. Not bad.

Compare this to Microsoft's approach:

1. Bug reported to Microsoft.
2. Microsoft ignores bug report for several weeks.
3. Bug reported again to Microsoft.
4. Microsoft again ignores bug report.
5. Bug discoverer goes public with report.
6. Microsoft complains about bug reporter disclosing bug before a patch was developed. Mentions "irresponsible" bug reporting.
7. Microsoft PR machine kicks in, spewing crap about "mitigating factors", "we don't know of any customer's compromised by this bug", and generally trying to downplay the bug's seriousness.
8. Microsoft develops patch, released during their regular monthly patch cycle, possibly as much as 4 weeks after patch development.
9. Microsoft crows about how they are proactive about security.


Total time: 4 weeks to several years, sometimes approaching infinity.

What I mean by that last statement is this:
There are known security holes in Windows 95 that Microsoft has known about since it's release or shortly thereafter, which have never been fixed, and which now never will be, because that product has been EOL'd.
View all 2 replies
This is already fixed in firefox 1.0.3 !!!
by Peter Reaper April 19, 2005 2:16 AM PDT
This is already fixed in Firefox 1.0.3 !!!

The article title and text are very misleading. It should have made more clear that all the listed vulnerabilities are ALREADY fixed in the current version of Firefox.
Open Source = Peer Review
by aabcdefghij987654321 April 18, 2005 9:40 AM PDT
Step 1: search bugzilla database
Step 2: write article
Step 3: profit!
Reply to this comment
Ha Ha Ha Ha.
by April 18, 2005 10:03 AM PDT
Reality sucks, doesn't it :-)
Reply to this comment
act your age
by April 18, 2005 12:21 PM PDT
we don't need no one-liners.
View reply
Firefox is like a sieve!
by alegr April 18, 2005 10:55 AM PDT
Folks,

Download Firefox sources, search for 'sprintf', and behold the wonders of buffer overflows! Pick any 'sprintf' call and figure out how to exploit it.
I haven't even looked for 'strcpy' and 'strcat' flaws yet.
Reply to this comment
Prove it
by pcLoadLetter April 18, 2005 8:06 PM PDT
Lets see some proof No, I am not going to go through all those files. You claim you did, now prove it.

I seriously doubt that an open source project whose code has been seen by thousands has these types of freshman level errors.
View reply
No.
by System Tyrant April 18, 2005 11:40 AM PDT
They've already got a fix for it.
Reply to this comment
Yes, but...
by catchall April 18, 2005 5:22 PM PDT
Many of the largest worm/virus outbreaks on the Window's platform came from flaws that had already been patched. For several of them, the patches had been out for months. It wasn't an excuse for MS, why should that be an excuse for FireFox?
Story mistitled -- should be "Mozilla patches flaws"
by M C April 18, 2005 12:10 PM PDT
This kind of reporting is irresponsible. The reporter has actually withheld information vital to the readers: that a patch has been in existence for days.

Then, at the very end of the article it alludes in the weakest possible terms to the existence of a patch. Readers who get googly-eyed by the techincal stuff in the body of the article will miss it entirely, possibly causing them to run unpatched and vulnerable.

CNet, why don't you try and HELP the computing community sometime?
Reply to this comment
I agree - bad report
by drhamad April 18, 2005 12:27 PM PDT
The only mention of a patch in this whole report is "vulnerable in versions previous to 1.0.3 / 1.7.7), which have been available for days. This report makes it sound like it's the end of the world, when it has already been patched.
View reply
This is already fixed in firefox 1.0.3 !!!
by Peter Reaper April 19, 2005 2:25 AM PDT
> CNet, why don't you try and HELP the computing community sometime?

Agreed, very irresponsible reporting (again) by CNET. :-(
still not enough to switch to IE
by April 18, 2005 12:12 PM PDT
I still think the open method will prevail over anything M$ can buy.
Reply to this comment
Crap Code
by April 18, 2005 12:32 PM PDT
It's not about the Open method VS Proprietary.

It's about crappy code, which can easily exist on any OS, in any programming language, under any model - despite the hype!

As an industry we should focus more on writing solid code, and less on whether or not software is "Open".

- - -

"Beneath the noble birth, between the proudest words, behind the beauty, cracks appear..." - Rush
View reply
6 Years in Making and Still...
by April 18, 2005 1:34 PM PDT
6 Years in Making (from a failed project's source codes aka netscape & mozilla) and Still Does not Work! :) Stallman & CO, said its will be flawless, solid, best, what happend ?

Get Life, Get IE.
www.microsoft.com/windows/IE
Reply to this comment
why?
by unknown unknown April 18, 2005 2:15 PM PDT
It doesn't matter which browser you use, the finding of a flaw in it is envitable. Software is written by humans and humans make mistakes. Firefox has only been around since late 2002 (called Phoenix then). There have been some significate changes made since Mozilla branched off Netscape and even more changes for Firefox. When make changes to code there is risk of introducing new bugs.

Get a life, drop the fanboy attitude.
...And IE is "perfect"?...
by J. Warren April 19, 2005 7:00 AM PDT
Best you check this:
- http://secunia.com/product/11/#advisories

...and make some comparisons first.
They've been patch why report on them now? (not text)
by unknown unknown April 18, 2005 1:57 PM PDT
<EOM>
Reply to this comment
I would like to thank...
by System Tyrant April 19, 2005 7:00 AM PDT
Scott Graham for his link. I went over to Secunia to view the 3 non critical Firefox bugs and stayed to view the many more unfixed non critical and critical bugs that IE has left unpatched. I would suggest anybody who wants to learn more go on over there and take a look

http://www.secunia.com
Reply to this comment
perspective
by tlite722 April 19, 2005 11:21 AM PDT
oh so true that IE has many more advisories than Firefox but to keep things in perspective lest you give the impression that firefox is bulletproof...

Firefox advisories on Secunia since launch - 15
IE6 advisories in the same period - 22

Firefox advisories in 2005 - 11
IE6 advisories in 2005 - 5

Again, as FF gains in popularity, it will gain the attention of those that would look for ways to do some bad. IE's just got a longer head start than FF in which to point out its flaws so it seems easier. The reality is that all software is flawed and no one can perfectly develop complex software...period.
View reply
So why not focus on the fix instead of the risk?
by Kelson April 19, 2005 2:11 PM PDT
If people don't update, maybe it's because (a) they don't realize it's important, and (b) they don't realize the fix is available. Stories like this have the opportunity to inform people on both counts. But this story actually manages to *hide* the fact that the update is available. Even allowing for sensationalism, something like "Firefox Security Holes Found, Fixed" with a sidebar pull-out of "Update to 1.0.3 to be protected" could succeed at both sensationalism and responsible reporting.
Reply to this comment
That was supposed to be a rely to "JUST LIKE MS"...
by Kelson April 19, 2005 2:13 PM PDT
I must've clicked on the wrong link or something.
(42 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right